Kazakhstan - AI Regulatory Amendments (232-VIII)

Law of the Republic of Kazakhstan on Amendments and Additions to the Code of Administrative Offences

Закон РК о внесении изменений и дополнений в Кодекс об административных правонарушениях

Kazakhstan

RAI-KZ-NA-RKAACXX-2025
Effective: January 17, 2026
In Force(In Force)
ActRisk ManagementTransparency and Disclosure
Export PDF

This Act (No. 232-VIII), adopted 17 November 2025, amends the Code of Administrative Offences of the Republic of Kazakhstan by adding Article 641-1 to impose administrative liability for breaches of the new AI legal framework. It establishes obligations for owners/operators of AI systems (transparency labelling of synthetic outputs, risk management for high-risk systems), reporting and documentation requirements, and a graded system of administrative fines and remedial measures.

Overview

The Law of the Republic of Kazakhstan on Amendments and Additions to the Code of Administrative Offences (No. 232-VIII) was adopted by the Parliament and signed by the Head of State on 17 November 2025. It supplements the Code by adding Article 641-1, which creates an administrative offence for violations of the AI regulatory regime introduced by the companion AI Act. The amendment targets transparency and risk-management failures by owners and operators of AI systems and establishes a tiered administrative penalty framework (monetized by monthly calculation index — MRP). For the official AI law and related texts see the national legal information system at Adilet: Law on Artificial Intelligence (No. 230-VIII) and the consolidated Code at Adilet: Code of Administrative Offences.

Definitions

Article 641-1 relies on the definitions introduced by the companion AI law. Key terms include: "artificial intelligence (AI)", "AI system", "owner/owner-operator of a system", "synthetic output" (any content generated wholly or partially by AI that may be mistaken for human-created content), "high-risk AI system" (systems that because of intended purpose may cause significant harm to health, rights, or public order), and "monthly calculation index (MRP)" used to quantify fines. The amendment uses the statutory taxonomy established by the AI Act, and readers should cross-reference those definitions in the primary AI Act text available at Adilet (AI Act).

Governance and Institutional Framework

The amendment assigns administrative enforcement competence to agencies and supervisory bodies charged with AI oversight by the primary AI law. The new institutional architecture concentrates technical supervision, registration and market surveillance functions primarily within bodies referenced in the AI Act and national digital governance structures; operational coordination is expected to involve the Ministry responsible for AI and digital development, sectoral regulators, and control organs (e.g., state inspection, prosecutor’s office on procedural matters where required). For background on the executive-level architecture and the new ministry, see reporting on the formation of the Ministry of Artificial Intelligence and Digital Development (MAIDD) and government communications such as Tengrinews: MAIDD announcement. The administrative procedure for imposing fines follows the procedural rules of the Code of Administrative Offences (investigation, notice, right to defense, appeal).

Key Focus Areas

The amendment concentrates on two core areas: transparency and risk management. Transparency: owners/operators of AI systems must ensure that users are informed where outputs are synthetic or generated by an AI system in a manner that could reasonably mislead consumers or third parties; omission constitutes an administrative offence. Risk management: owners/operators of AI systems classified as high-risk under the AI Act are required to perform systematic risk identification, assessment, mitigation, testing and continuous monitoring; failure to carry out those measures — when it results in detrimental consequences to health, rights, public order, or other protected interests — is actionable under Article 641-1 provided the conduct does not amount to a criminal offense. The law therefore operationalizes supervisory reliance on documented risk management practices and transparency labeling as the threshold for administrative responsibility.

Implementation Framework

Enforcement is administrative: violations are investigated under the Code’s procedures and sanctions imposed by authorized administrative bodies. The law supports a compliance ecosystem: obligations to keep logs, retain risk assessments and test records, produce incident reports on request, and cooperate with market surveillance. For AI systems deemed high-risk, the implementing regulations (to be adopted by relevant ministries and oversight bodies) will specify technical standards for risk management, record formats, and reporting channels. Stakeholders should consult the consolidated Code at Adilet (Code) and the companion AI Act at Adilet (AI Act) for linkage and procedural rules.

Monitoring and Evaluation

Monitoring will combine routine administrative inspections, market surveillance, and reactive investigation of incidents reported by users or discovered by supervisory agencies. The law contemplates periodic review of enforcement outcomes, repeat-offender tracking (repeated breaches within 12 months trigger escalated fines and remedial actions), and the collection of compliance metrics to feed policy evaluation. Ministries and agencies are expected to publish enforcement statistics and guidance to clarify expectations for system design, documentation and labelling.

Penalties, Liability, and Appeals

Penalties are administrative fines denominated in MRP (monthly calculation indices). The statutory schedule introduced by Article 641-1 includes first‑instance fines (e.g., 15 MRP for individuals; 20 MRP for small entities; 30 MRP for medium entities; 100 MRP for large enterprises) and elevated fines on repeat violations within one year (e.g., up to 30, 50, 70 and 200 MRP respectively). Repeat or severe breaches may also attract suspension or prohibition of an AI system and other remedial measures. Administrative decisions are subject to appeal in the administrative and judicial channels prescribed by the Code of Administrative Offences, consistent with procedural safeguards and rights to defense.

Relationship to Other Instruments

The amendment is a companion enforcement instrument to the substantive AI Act (No. 230‑VIII) and supplementary legislative changes to consumer protection and data protection regimes. It does not replace criminal liability where the same act meets criminal law elements; instead it provides a calibrated administrative enforcement pathway. Entities must also comply with personal data protection laws, consumer protection rules, sectoral regulation (e.g., healthcare, finance) and any technical standards issued by sector regulators. See the AI Act and consolidated Code for cross-references: AI Act (Adilet), Code (Adilet).

International Alignment

The design of Article 641-1 — focusing on transparency, risk management, documentation and proportionate administrative sanctions — reflects international trends in AI governance (e.g., risk-based regulation, mandatory transparency for synthetic content, documentation and traceability). The law is intended to foster compatibility with international regulatory approaches while reflecting Kazakhstan’s domestic legal architecture. Stakeholders operating cross-border services should therefore prepare for both domestic administrative enforcement and possible international data/market compliance obligations.

Implementation Timeline

EventDate
Adoption by Parliament / Signature by Head of State2025-11-17
Official publication (press/gazette)2025-11-18 (published in national print and legal registries)
Common entry-into-force (subject to law text)Generally within statutory term (often 60 days after publication) — estimated 2026-01-15; consult official publication for exact implementation clauses
Start of enforcement of administrative offences (first stage)As per entry-into-force provisions or implementing regulations (see official registry)

Compliance Checklist

RequirementYes/No (Action)
Identify whether deployed AI systems are classified as high-riskYes — perform classification & document
Implement risk management framework (assessment, mitigation, testing)Yes — create and retain assessment records
Label synthetic outputs and notify usersYes — automated or manual notification systems
Maintain logs, test reports and incident recordsYes — retention policy & secure storage
Prepare incident reporting and mitigation plansYes — integrate into operations

Sources and References

SourceType
Law of the Republic of Kazakhstan "On Artificial Intelligence" (No. 230‑VIII) — AdiletPrimary Source
Code of Administrative Offences (consolidated) — AdiletPrimary Source
Zakon.kz legal database (listing of new acts incl. No. 232‑VIII)Primary/Official registry
Government press & registry notices — gov.kzOfficial announcement
Plain English

Kazakhstan's new law introduces administrative penalties for owners and operators of Artificial Intelligence (AI) systems who fail to meet specific requirements under the country's new AI regulatory framework. This measure, effective January 17, 2026, amends the Code of Administrative Offences to ensure transparency and responsible risk management in AI deployment.

The law applies to anyone owning or operating an AI system within Kazakhstan. Its primary goal is to hold these entities accountable for how their AI systems interact with users and the public. Key obligations include: - Ensuring users are clearly informed when an AI system generates "synthetic output"—any content that could be mistaken for human-created material. Failing to label such content is an administrative offense. - For "high-risk AI systems"—those with the potential to cause significant harm to health, rights, or public order—owners and operators must implement a systematic risk management framework. This involves identifying, assessing, mitigating, testing, and continuously monitoring risks. Failure to do so, especially when it leads to detrimental consequences, can trigger penalties. - Maintaining thorough documentation, including logs, risk assessments, test reports, and incident records, is also mandatory to demonstrate compliance.

Violations of these rules can result in administrative fines, calculated using a "monthly calculation index" (MRP). Fines vary significantly based on the size of the entity and whether it's a first-time or repeat offense. For instance, initial fines can range from 15 MRP for individuals to 100 MRP for large enterprises, escalating to up to 200 MRP for repeat breaches within a year. Severe or repeated non-compliance could also lead to the suspension or outright prohibition of an AI system. All administrative decisions are subject to appeal.

A practical pitfall for businesses is the emphasis on *documented* compliance. It's not enough to simply manage risks or label synthetic content; you must be able to prove these actions through comprehensive records and reports. This means establishing robust internal processes for logging, testing, and incident reporting well before the effective date.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 8 marked complete

Plain-English obligations under Kazakhstan - AI Regulatory Amendments (232-VIII). Not legal advice — verify against the official text before relying on it.

  1. #1CriticalArticle 641-1Jan 17, 2026

    Applies to: Owners and operators of AI systems.

    owners/operators of AI systems must ensure that users are informed where outputs are synthetic... omission constitutes an administrative offence.
  2. #2CriticalArticle 641-1Jan 17, 2026

    Applies to: Owners and operators of high-risk AI systems.

    owners/operators of AI systems classified as high-risk... are required to perform systematic risk identification, assessment, mitigation, testing and continuous monitoring.
  3. #3ImportantArticle 641-1Jan 17, 2026

    Applies to: Owners and operators of AI systems.

    Identify whether deployed AI systems are classified as high-risk
  4. #4ImportantArticle 641-1Jan 17, 2026

    Applies to: Owners and operators of AI systems.

    obligations to keep logs, retain risk assessments and test records
  5. #5ImportantArticle 641-1Jan 17, 2026

    Applies to: Owners and operators of AI systems.

    Prepare incident reporting and mitigation plans
  6. #6ImportantArticle 641-1Jan 17, 2026

    Applies to: Owners and operators of AI systems.

    produce incident reports on request
  7. #7ImportantArticle 641-1Jan 17, 2026

    Applies to: Owners and operators of AI systems.

    cooperate with market surveillance.
  8. #8ImportantArticle 641-1Jan 17, 2026

    Applies to: Owners and operators of high-risk AI systems.

    implementing regulations... will specify technical standards for risk management, record formats, and reporting channels.

© Regulations.AI — created on 13-Jun-2026