Kazakhstan - AI Regulation (2025)
Draft Law 'On Artificial Intelligence'
Draft Law (Bill) 'On Artificial Intelligence' — parliamentary bill submitted/considered (Проект Закона «Об искусственном интеллекте»)
Kazakhstan
RAI-KZ-NA-DAIPSXX-2025Kazakhstan - AI Regulation (2025) is In Force (Amended) in Kazakhstan as of 10 Sep 2026, according to adilet.zan.kz.
ActGovernance and OversightRisk ManagementIn May 2025 the Mazhilis (lower chamber) of the Parliament of Kazakhstan approved in first reading a dedicated Draft Law "On Artificial Intelligence" establishing a national, risk-based legal framework for AI. The bill (7 chapters, 28 articles) sets out principles (legality, transparency, human-centredness), a three-tier risk classification, prohibitions on certain autonomous and manipulative systems, requirements for labelling synthetic content, documentation and risk-management obligations for owners and operators, and foundations for a national AI platform and conformity mechanisms.
Summary
A parliamentary bill titled 'On Artificial Intelligence' was presented and considered in 2025 and establishes a national legal framework for development, deployment and use of AI systems, including risk-based classification, obligations for owners and operators, transparency requirements and prohibited AI functions. The finalized law was passed by Parliament and enacted later in 2025; the consolidated text is published in the official legal information system.
Full article
Read full text ↗Overview
The Draft Law "On Artificial Intelligence" establishes a unified national legal framework for the development, deployment and use of artificial intelligence (AI) systems across the Republic of Kazakhstan. The statute treats AI as an object of informatization and sets out foundational legal principles — including responsibility, safety, transparency and human oversight — intended to guide both public and private actors engaged with AI technologies. The text creates specific obligations for owners, operators, developers and users of AI systems, and provides legal bases for the creation and operation of a National AI Platform, for sectoral governance instruments, and for conformity and supervisory mechanisms to verify compliance. The legislative package follows a risk-based approach to differentiate duties according to the potential impact of particular systems on safety, rights and public interests. The finalized law was passed by Parliament and signed by the President in 2025; the consolidated text is published in the national legal information system (primary legal text available at: https://adilet.zan.kz/rus/docs/Z2500000230?utm_source=openai).
Definitions
The law introduces and clarifies the principal legal concepts required to determine the scope of regulatory coverage and to trigger specific statutory obligations. Key defined terms include, among others, "artificial intelligence", "model", "system", "data library" (defined as a library of data used for training), and "synthetic result" (AI-generated content). The statute also provides related technical and operational notions necessary to delimit which products and services fall within scope. These definitions operate as legal thresholds: whether an instrument is captured as an AI system under the law determines the applicability of duties such as documentation, transparency, labelling of synthetic outputs, and registration or conformity requirements. For the exact statutory language and comprehensive list of defined terms, see the consolidated text at: https://adilet.zan.kz/rus/docs/Z2500000230?utm_source=openai.
Governance and Institutional Framework
The bill defines roles and responsibilities for central government authorities in AI policy-making, oversight and enforcement. It designates a competent authority (or authorities) charged with supervision, grants powers to expand government competence to form and execute AI policy, and envisages inter-agency coordination mechanisms to address sectoral risks such as safety, personal data protection and national security. The statute provides legal foundations for establishing a National AI Platform intended to serve as controlled infrastructure for model development, testing and deployment under prescribed conditions. Delegated authority is provided to competent bodies to adopt secondary regulations, technical standards and operational rules necessary to implement substantive obligations, including supervisory procedures and conformity assessment regimes. For statutory details and enumerated powers, consult the official consolidated text at: https://adilet.zan.kz/rus/docs/Z2500000230?utm_source=openai.
Key Focus Areas
- Risk-based classification — the law establishes a three-tier framework to categorise AI systems according to their potential impact on safety, fundamental rights and public interests. Obligations are differentiated by risk tier so that higher-risk systems are subject to more stringent controls and oversight.
- Prohibited functionalities — the statute specifies explicit prohibitions on certain AI uses, including manipulative or covert behavioural influence technologies and particular forms of biometric surveillance in public spaces absent a lawful basis; such prohibitions aim to mitigate systemic harms and protect civil liberties.
- Transparency and labelling — the bill mandates labelling of synthetic content and AI-generated goods or services. For specified outputs, machine‑readable labelling requirements are introduced alongside human‑readable disclosure obligations to ensure users can recognise when content or decisions are produced by AI systems.
- Documentation and technical records — developers, owners and operators must maintain technical documentation and records (technical specifications, data provenance logs, summaries of model architecture, testing reports and other materials) to enable supervisory review, audits and conformity assessments.
- Risk management and testing — owners and operators are required to implement lifecycle risk‑management systems, conduct risk assessments, carry out pre‑deployment testing and, for systems assessed as higher risk, submit to audits or conformity assessments prior to and during deployment.
- Governance instruments — the law establishes registration or listing regimes for specified categories of systems, sets out conformity assessment mechanisms, confers supervisory powers on competent authorities and provides the legal basis for operating a National AI Platform to support controlled development and verification activities.
Implementation Framework
The statute applies to systems and products that meet the statutory definition of AI and to natural and legal persons who develop, own, deploy or operate such systems within Kazakhstan’s jurisdiction. It covers both the public and private sectors and sets differentiated obligations according to a system’s risk classification and its context of use, with particular emphasis on public services, critical infrastructure and mass media applications. Mandatory measures include maintaining up-to-date documentation and technical records, performing risk assessments, completing pre-deployment testing and subjecting certain systems to audits and conformity assessments. Where required by the law or by delegated rules, specified systems must be registered or listed with competent authorities. The law grants delegated authority to competent bodies to issue implementing regulations, technical standards and operational guidance (including procedures governing access to and use of the National AI Platform). Full procedural and operational details are to be developed through the secondary regulations referenced in the consolidated legal text: https://adilet.zan.kz/rus/docs/Z2500000230?utm_source=openai.
Monitoring and Evaluation
The law creates supervisory powers for the designated competent authority(ies) to monitor compliance with statutory obligations, to require submission of documentation and technical records, and to conduct conformity assessments and audits where necessary. Supervisory measures include the ability to inspect systems, demand corrective actions, and mandate periodic reporting. Enforcement is designed to ensure transparency, data protection and safety obligations are observed throughout the lifecycle of AI systems. The statute foresees inter‑agency coordination to monitor systemic risks affecting national security, information security and public safety, and anticipates the issuance of delegated rules and standards to allow technical verification and ongoing evaluation of AI system performance and safety. The legislative process included stakeholder consultations, public hearings and expert panels; the law foresees continuation of stakeholder engagement during implementation to inform secondary regulations and standards.
Penalties, Liability, and Appeals
The statutory package establishes administrative liability for statutory violations and provides competent authorities with supervisory enforcement powers to secure compliance. Amendments to the Administrative Offences Code have been processed alongside the AI law to specify administrative sanctions and enforcement modalities. The law also contemplates civil liability pathways and mechanisms for redress in cases where AI systems cause harm, and it includes provisions encouraging or mandating insurance arrangements to cover potential damages arising from AI use (the Senate recommended strengthening insurance measures during parliamentary review). Procedures for appealing administrative decisions and modalities for civil claims are framed by references to existing administrative and civil liability regimes; detailed procedural rules and sanction scales are set out in the consolidated text and in delegated implementing acts (see consolidated law: https://adilet.zan.kz/rus/docs/Z2500000230?utm_source=openai).
Relationship to Other Instruments
The law interacts with and requires harmonisation across multiple existing legal regimes, including data protection and privacy law, information and media regulation, consumer protection statutes, administrative offences and civil liability frameworks. It interfaces with broader government strategic initiatives such as the national AI development concept (AI Concept 2024–2029). The legislative package contains cross‑references and accompanying amendments to related codes and statutes intended to align responsibilities among regulators and to eliminate conflicts; many of these harmonising amendments were processed as part of the overall legislative package. Additional related acts and harmonising amendments are reflected in the official legislative materials and secondary instruments referenced in the consolidated text: https://adilet.zan.kz/rus/docs/P2400000592?utm_source=openai.
International Alignment
The statute has been drafted to align with prevailing international AI regulatory trends while reflecting Kazakhstan’s national policy priorities. In shaping the bill, drafters sought to balance objectives of safety, fundamental rights protection and innovation‑friendly governance. The law’s risk‑based approach, transparency and conformity mechanisms correspond to common elements found in international AI policy discussions and standards-setting processes. Implementing regulations are expected to take international technical standards and cooperative arrangements into account where appropriate to facilitate interoperability, cross‑border verification and technical harmonisation.
Implementation Timeline
| Date | Event |
|---|---|
| 2025-03-03 | Public presentation of draft law in Majilis |
| 2025-05-14 | Majilis — first reading (approved) |
| 2025-09-24 | Majilis — second reading (approved) |
| 2025-10-23 | Senate returned bill to Majilis with amendments |
| 2025-11-17 | Presidential signature (reported) |
Sources and References
| Source | URL |
|---|---|
| National legal information system — consolidated law text (Kazakhstan) | https://adilet.zan.kz/rus/docs/Z2500000230?utm_source=openai |
| National legal information system — related legislative acts and cross-references | https://adilet.zan.kz/rus/docs/P2400000592?utm_source=openai |
Requirements for a company
What an organisation has to do under Kazakhstan - AI Regulation (2025), at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Must do
12- Do not deploy manipulative or covert behavioral influence AI systems.Developers, owners, and operators of AI systems.
- Do not deploy biometric surveillance in public spaces without a lawful basis.Developers, owners, and operators of AI systems.
- Determine your AI system's risk category under the three-tier framework.Developers, owners, and operators of AI systems.
- Label all synthetic content and AI-generated outputs.Developers, owners, and operators of AI systems.
- Ensure users can recognize when content or decisions are AI-produced.Developers, owners, and operators of AI systems.
- Maintain mandatory technical documentation and records for your AI system.Developers, owners, and operators of AI systems.
- +6 more in the table below
Must not do
0Nothing in this category.
Should do
0Nothing in this category.
Should not do
0Nothing in this category.
Who must do what
The obligations under Kazakhstan - AI Regulation (2025), most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Developers, owners, and operators of AI systems. | Do not deploy manipulative or covert behavioral influence AI systems. “specifies explicit prohibitions on certain AI uses, including manipulative or covert behavioural influence technologies” | — | — | Critical |
| 2 | Developers, owners, and operators of AI systems. | Do not deploy biometric surveillance in public spaces without a lawful basis. “prohibitions on ... particular forms of biometric surveillance in public spaces absent a lawful basis” | — | — | Critical |
| 3 | Developers, owners, and operators of AI systems. | Determine your AI system's risk category under the three-tier framework. “the law establishes a three-tier framework to categorise AI systems” | Before deployment | — | Critical |
| 4 | Developers, owners, and operators of AI systems. | Label all synthetic content and AI-generated outputs. “the bill mandates labelling of synthetic content and AI-generated goods or services.” | — | — | Critical |
| 5 | Developers, owners, and operators of AI systems. | Ensure users can recognize when content or decisions are AI-produced. “ensure users can recognise when content or decisions are produced by AI systems.” | — | — | Critical |
| 6 | Developers, owners, and operators of AI systems. | Maintain mandatory technical documentation and records for your AI system. “developers, owners and operators must maintain technical documentation and records” | — | — | Critical |
| 7 | Owners and operators of AI systems. | Implement and maintain an enterprise risk management system for your AI system. “owners and operators are required to implement lifecycle risk‑management systems” | — | — | Critical |
| 8 | Owners and operators of AI systems. | Conduct risk assessments and pre-deployment testing for your AI system. “conduct risk assessments, carry out pre‑deployment testing” | Before deployment | — | Critical |
| 9 | Owners and operators of higher-risk AI systems. | Submit higher-risk AI systems to audits or conformity assessments. “for systems assessed as higher risk, submit to audits or conformity assessments” | Prior to and during deployment | — | Critical |
| 10 | Owners and operators of specified AI systems. | Register or list specified AI systems with competent authorities. “Mandatory measures include... registering or listing systems where required” | Prior to operation | — | Critical |
| 11 | Owners and operators of AI systems. | Arrange insurance or financial coverage for potential AI system damages. “includes provisions encouraging or mandating insurance arrangements to cover potential damages arising from AI use” | Before deployment | — | Important |
| 12 | Owners and operators of AI systems. | Provide mechanisms for users to challenge automated decisions and seek redress. “contemplates civil liability pathways and mechanisms for redress in cases where AI systems cause harm” | Upon deployment | — | Important |
Related Regulations
More AI regulation in Kazakhstan
© Regulations.AI · updated on 13 Jun 2026 · reviewed against official sources on 10 Sep 2026