Morocco - National AI Governance Bill (2024)

Bill for the Establishment of the National Agency for AI Governance

Projet de loi pour l'établissement de l'Agence nationale de gouvernance de l'IA

Morocco

RAI-MA-NA-ENAAGXX-2024
Proposed(Officially filed for action)
BillGovernance and OversightConformity Assessment and RegistrationRisk Management
Export PDF

A bill submitted to Morocco's House of Councilors in April 2024 by the Moroccan Labor Union parliamentary group proposing the establishment of a National Agency for Artificial Intelligence to oversee AI governance, develop national strategies, and ensure compliance with ethical standards.

Overview

The Bill for the Establishment of the National Agency for AI Governance proposes creation of an independent public authority responsible for national AI strategy, regulatory coordination, oversight, and enforcement to ensure safe, ethical and sovereign deployment of artificial intelligence across Morocco. The draft envisions the Agency setting national AI policy, coordinating oversight across sectors, and enforcing compliance with ethical, safety, privacy and security standards to harmonize AI governance across public and private sectors, align Moroccan policy with international norms, and protect fundamental rights while promoting innovation. The concept aligns with government initiatives to develop a national AI roadmap and multi-stakeholder consultations on AI policy. See recent ministry communications: mmsp.gov.ma - Assises Nationales de l'IA. The drafting discussions indicate momentum for formal legislation, but an authorized consolidated draft law published in an official government legislative database or in the Official Gazette was not located for 2024.

Definitions

The Bill sets out operational, technology-neutral definitions intended to maximize legal clarity and interoperability. Key defined terms described in the draft include "artificial intelligence system," "high-risk AI system," "developer/provider," "deployment," "automated decision-making," and "personal data processing". Definitions are intended to be aligned with international instruments and to provide a foundation for scope, compliance obligations, and enforcement. The Bill also contemplates definitions that enable a risk-based approach to classification and regulation of systems operating in sensitive domains.

Governance and Institutional Framework

The Agency would be constituted as an independent administrative authority with a governing board composed of government representatives, independent experts, civil society and possibly industry observers, supported by technical units such as policy, risk assessment, inspections, research and capacity-building teams. The head of the Agency would be appointed by the executive branch with statutory safeguards intended to ensure operational independence. The Agency would collaborate with the Commission Nationale de Contrôle de la Protection des Données à Caractère Personnel (CNDP) on privacy and compliance matters; see CNDP communications: cndp.ma - Communiqué. The institutional architecture envisaged includes coordination mechanisms with sectoral regulators (health, education, finance, etc.) and formal interfaces with national data protection authorities to avoid regulatory overlap and to ensure coherent oversight across domains.

Key Focus Areas

  • Legal establishment and mandate of the Agency: creating a centralized authority for AI governance with a statutory remit for policy, oversight, and enforcement.
  • Technical and ethical guidance: powers for the Agency to issue technical standards, ethical guidelines, and sector-specific guidance to support safe deployment.
  • Risk-based classification: a framework to classify AI systems by risk level, including explicit categories for high-risk systems used in sensitive domains (health, justice, social services) and systems materially affecting Moroccan residents or critical infrastructure.
  • Registration and conformity assessment: requirements for registration/notification of specified AI systems and pre-deployment conformity assessments for high-risk systems.
  • Audit, inspection and enforcement powers: authority to conduct audits and inspections, require corrective actions, suspend or withdraw systems, and impose administrative fines calibrated by severity and recurrence.
  • Rights for individuals: transparency obligations, the right to information about automated decisions affecting individuals, remedies and complaint channels, and data protection safeguards.
  • Provider obligations: documentation and accountability, risk assessment and mitigation, impact assessments for high-risk systems, record-keeping, and cooperation with the Agency for audits and corrective measures.
  • Regulatory sandboxes and national infrastructure: authority to operate sandboxes and to support national AI infrastructure intended for public-interest models and capacity-building.
  • Exemptions and transitional measures: contemplated exemptions or tailored transitional provisions for research and small-scale developers to preserve innovation while moving toward comprehensive oversight.

Implementation Framework

The Bill anticipates a phased implementation model and a set of operational mechanisms to bring systems into compliance. Compliance mechanisms described include mandatory registration or notification for specified categories of AI systems, pre-deployment conformity assessments for high-risk AI, periodic post-market monitoring, incident reporting obligations, algorithmic documentation and "explainability" requirements, and privacy-by-design data governance standards. Entities would be required to perform algorithmic impact assessments and technical testing prior to large-scale deployment of certain systems. The Agency would be empowered to establish regulatory sandboxes to facilitate experimentation and to operate or coordinate national AI infrastructure for public-interest models. The Bill would also contemplate transitional provisions to mitigate burdens on research activities and small developers while enabling regulatory objectives.

Monitoring and Evaluation

Monitoring and evaluation mechanisms in the draft include periodic post-market monitoring, mandatory incident reporting, audit and inspection regimes, and obligations for providers to maintain records and documentation for review. The Agency would carry out risk-based monitoring and could require corrective actions or technical remediation following inspections or investigations. Performance indicators and ongoing stakeholder consultations are anticipated to refine technical standards over time. The Bill anticipates coordination between the Agency and sectoral regulators and the CNDP for privacy-related compliance monitoring.

Penalties, Liability, and Appeals

The Agency would be empowered to impose administrative sanctions, including fines, and to order suspension or withdrawal of non-compliant systems. Sanctions would be calibrated according to the severity and recurrence of violations, with enhanced measures for breaches that affect fundamental rights or critical infrastructure. Procedural safeguards would be provided, including rights to appeal Agency decisions and judicial review. The draft signals intent to balance deterrence and proportionality in enforcement while preserving mechanisms for due process and redress.

Relationship to Other Instruments

The Bill is intended to operate alongside Morocco’s existing data protection law and the CNDP’s oversight, as well as applicable sectoral laws in health, education, finance, and other regulated domains. It anticipates formal coordination mechanisms with the CNDP for personal data matters and with sectoral regulators to avoid regulatory overlap and to enable domain-specific governance. The architecture seeks to align national requirements with existing legal frameworks to provide legal certainty for public-sector organizations and private providers operating in Morocco.

International Alignment

The draft is designed with an eye toward alignment with international norms and evolving guidance from multilateral bodies. It references the goal of interoperability with international instruments and evolving EU/UN guidance to facilitate cross-border cooperation and consistency with widely-used governance approaches. Alignment priorities include technology-neutral definitions, a risk-based approach, and mechanisms for cooperation with foreign regulators to address cross-border services that materially affect Moroccan residents or infrastructure.

Implementation Timeline

DateEvent
2024-04-01Bill Submitted (reported submission to the legislature). This date is recorded in drafting metadata as 2024-04-01.
2024-04-01Anticipated immediate establishment of the Agency and governance bodies upon enactment (draft envisages immediate establishment as the first phase; subject to formal legislative process).
2024-10-01Target within 6 months for adoption of priority guidelines for public-sector AI (6–12 months target described in drafting discussions).
2025-04-01Target within 12 months for rollout of initial registration, conformity and sandbox frameworks (part of the 12–24 month rollout contemplated in the draft).
2026-04-01End of a 24-month rollout horizon for fuller implementation of registration, conformity assessment and sandbox frameworks (phased implementation over 12–24 months as anticipated in drafting discussions). Exact statutory timelines remain subject to the formal legislative and regulatory process.

Compliance Checklist

RequirementDescription
Registration / NotificationMandatory registration or notification for specified categories of AI systems, particularly those classified as high-risk or those materially affecting Moroccan residents or critical infrastructure.
Pre-deployment Conformity AssessmentConformity assessments required prior to deployment for high-risk AI systems, including technical testing and documentation review.
Algorithmic Impact AssessmentsRequirement to perform risk assessments and algorithmic impact assessments for systems that pose significant risks to rights, safety, or public interest.
Documentation & AccountabilityMaintenance of technical documentation, logs, and records to demonstrate compliance, enable audits, and support explainability obligations.
Incident ReportingObligations to report incidents, harms or breaches to the Agency within specified timeframes as part of post-market monitoring and enforcement regimes.
Data Governance & Privacy-by-DesignImplementation of data governance standards including privacy-by-design measures and cooperation with the CNDP for personal data protections.

Sources and References

SourceURL
Ministry communications on national AI dialogues (Assises Nationales de l'IA)https://www.mmsp.gov.ma/fr/actualites/AssisesNationalesDeIA2025?utm_source=openai
Ministry page on ministerial activitieshttps://www.mmsp.gov.ma/fr/la-ministre?utm_source=openai
Commission Nationale de Contrôle de la Protection des Données à Caractère Personnel (CNDP) communiquéhttps://www.cndp.ma/communique-de-presse-4/?utm_source=openai
Plain English

Morocco is considering a new law to create a National Agency for Artificial Intelligence, which would oversee how AI is developed and used across both public and private sectors in the country. This proposed law would apply to anyone developing, providing, or deploying artificial intelligence systems in Morocco, particularly those deemed "high-risk" or systems that significantly affect Moroccan residents or critical infrastructure. The aim is to ensure AI is deployed safely, ethically, and in line with national strategy.

The new Agency would establish national AI policy and coordinate oversight. Key obligations for those in scope would include: - Registering or notifying the Agency about certain AI systems, especially those classified as high-risk. - Conducting pre-deployment conformity assessments for high-risk systems, which involve technical testing and documenting how the system works. - Performing algorithmic impact assessments for systems that could pose significant risks to rights, safety, or public interest. - Maintaining detailed records and documentation to show compliance, and reporting any incidents or harms to the Agency. - Implementing data governance standards, including privacy-by-design, and working with Morocco's National Commission for the Control of Personal Data Protection (CNDP) on privacy matters.

While the bill was submitted in April 2024, the exact effective date is unknown. The Agency itself is expected to be established soon after the law passes, with a phased rollout of specific requirements like registration and conformity assessments anticipated over 12 to 24 months. If you don't comply, the Agency could impose administrative fines, order corrective actions, or even suspend or withdraw non-compliant systems. Penalties would be tougher for severe or repeated violations, especially those impacting fundamental rights or critical infrastructure. A practical challenge for businesses might be navigating the coordination required not just with this new AI Agency, but also with the existing CNDP for data protection and other sectoral regulators, despite the bill's intent to streamline oversight.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 10 marked complete

Plain-English obligations under Morocco - National AI Governance Bill (2024). Not legal advice — verify against the official text before relying on it.

  1. #1CriticalUpon enactment and framework rollout

    Applies to: Providers of specified AI systems.

    Mandatory registration or notification for specified categories of AI systems.
  2. #2CriticalBefore deployment

    Applies to: Providers of high-risk AI systems.

    Pre-deployment conformity assessments for high-risk AI systems.
  3. #3CriticalPrior to large-scale deployment

    Applies to: Entities deploying AI systems with significant risks.

    Entities would be required to perform algorithmic impact assessments... prior to large-scale deployment.
  4. #4CriticalUpon deployment and ongoing

    Applies to: Providers of AI systems.

    Maintenance of technical documentation, logs, and records to demonstrate compliance.
  5. #5CriticalWithin specified timeframes

    Applies to: Providers of AI systems.

    Obligations to report incidents, harms or breaches to the Agency within specified timeframes.
  6. #6CriticalUpon deployment

    Applies to: Providers of AI systems processing personal data.

    Implementation of data governance standards including privacy-by-design measures.
  7. #7CriticalPrior to large-scale deployment

    Applies to: Entities deploying certain AI systems.

    Entities would be required to perform... technical testing prior to large-scale deployment of certain systems.
  8. #8CriticalOngoing after deployment

    Applies to: Providers of AI systems.

    Periodic post-market monitoring.
  9. #9CriticalUpon deployment

    Applies to: Providers of AI systems making automated decisions.

    Transparency obligations, the right to information about automated decisions affecting individuals.
  10. #10CriticalUpon request

    Applies to: Providers of AI systems.

    Cooperation with the Agency for audits and corrective measures.

© Regulations.AI — created on 13-Jun-2026