Peru - AI Digital Labeling Bill (6524/2023)
Project 6524/2023 — Bill on digital labeling for systems and applications using Artificial Intelligence
Proyecto 6524/2023 — Bill on digital labeling for systems and applications using Artificial Intelligence (etiquetado digital)
Peru
RAI-PE-NA-P6DLSXX-2023Project 6524/2023 (presented November 27, 2023) proposes mandatory digital labeling ("etiquetado digital") for systems and applications that use artificial intelligence, requiring providers to disclose AI involvement in the creation, manipulation or interaction with digital content available to users in Peruvian territory. The draft sets transparency obligations, recordkeeping and audit powers for a competent authority while preserving that labeling does not replace consent obligations and contemplates limited, regulated exceptions.
Summary
Project 6524/2023 (Proyecto de Ley N° 6524/2023-CR), presented to the Peruvian Congress on November 27, 2023, is a legislative initiative that seeks to require digital labels indicating the use, generation or manipulation of digital content by systems or applications that employ Artificial Intelligence (AI). The objective of the bill is to provide consumers and users in Peru with proactive, clear and persistent notice when content they interact with — visual, audio, audiovisual or other digital outputs — has been created or materially manipulated by AI systems. The bill is explicitly framed as a transparency and consumer-protection measure, intended to reduce risks of deception caused by synthetic media (including deepfakes and 'ultra-falsification'), to support informed user decisions, and to enable oversight by a designated competent authority.
Scope and applicability: The proposal applies to providers — national or foreign — who offer AI-powered systems or applications and have users resident in Peruvian territory. It covers AI used in generation, transformation or manipulation of content and the delivery of automated interactions where users could reasonably expect human authorship. The text (as presented in public summaries and legislative communications) emphasizes that labeling must be proactive and prominent, and that it complements but does not replace requirements for informed consent where such consent is required by other laws (for example, privacy or biometric processing rules).
Key obligations and mechanisms: The draft requires that any AI-generated or AI-manipulated content that could be mistaken for authentic human-produced content be clearly labeled as such. It contemplates technical and procedural requirements for labels, recordkeeping obligations (audit logs, provenance metadata), and periodic audits by a designated authority. The bill contemplates regulatory detailing (secondary regulations) that will specify formats, exceptions, and enforcement mechanics. The authority would be empowered to perform audits and impose sanctions for noncompliance.
Risk focus and limits: The proposal targets transparency as a mitigating measure against misinformation, impersonation and harms to reputation or democratic processes. It also contemplates exceptions where full disclosure would be disproportionate or where national security, ongoing investigations or other justified reasons apply, to be defined in regulation. The draft clarifies that labeling alone is insufficient to legitimize uses otherwise prohibited by law (e.g., privacy intrusions, fraud) and that existing data protection and consumer protection regimes remain applicable.
Regulatory and institutional relationships: While the bill text summaries do not in all cases specify a single named enforcement agency, Congressional communications accompanying the initiative state that a competent authority will have powers to verify compliance and carry out audits. In practice, market surveillance and consumer protection authorities (notably INDECOPI) are likely candidates to take enforcement roles alongside sectoral regulators. The bill is presented as complementary to other Peruvian AI and digital governance initiatives and is intended to align with international trends on AI transparency and synthetic media labeling.
Legislative status: As of its presentation in late 2023 the bill remained in draft stage and subject to committee review and stakeholder consultations (commissions, public hearings). The initiative has been discussed in committee events and workgroups considering multiple AI-related bills. Public reporting and legal analysis of the proposal are available through legislative communications and legal-sector briefings.
Full article
Read full text ↗Overview
Project 6524/2023, presented to the Congress of the Republic of Peru on 27 November 2023, proposes a legal regime for mandatory digital labeling ("etiquetado digital") of systems and applications that employ Artificial Intelligence when producing, manipulating or mediating digital content. The bill's stated aim is to provide users in Peruvian territory with proactive and intelligible notice of AI involvement to reduce deception and to support informed decision-making. Legislative communications and legal analyses published after the presentation summarize the initiative and its core obligations; see for example the congressional communication on the bill's presentation and summary coverage in legal press. For additional background see Congress communications (Huánuco) and practitioner commentary at CMS - TMC Legal bytes.
Definitions
The proposal defines core terms such as "Digital Labeling" (etiquetado digital) to mean the process of identifying and classifying the intervention of AI in creation, development or interaction of digital content. "AI system" is understood broadly to include machine learning models, generative models and automated decision systems used to create, transform or manipulate content. "Content" encompasses visual, audio, audiovisual and text-based outputs. The concept of "ultra-falsification" is used in the draft to identify synthetic content that closely resembles real persons, objects or events and that may mislead users.
Governance and Institutional Framework
The bill assigns supervisory and enforcement responsibilities to a "competent authority" empowered to conduct audits, verify compliance and impose sanctions. Although the draft summaries do not always name a single agency, the legislative communications describe the creation of procedures for the authority to audit labeling practices and require secondary regulation to set technical standards. In practice, enforcement will intersect with consumer protection and market surveillance institutions such as INDECOPI (consumer protection and competition) and sectoral regulators for finance, health and telecommunications. The bill envisions rulemaking (reglamento) to specify formats, exceptions and thresholds for obligations; see commentary at LP Derecho.
Key Focus Areas
The proposal centers on several interlocking policy areas: (1) Transparency: mandatory labeling of AI-generated or AI-manipulated content so users can distinguish synthetic outputs from human-created content; (2) Consumer protection: preventing deception and supporting informed consent; (3) Accountability and traceability: recordkeeping and provenance metadata for generated content; (4) Market surveillance: powers for audits and inspections by the competent authority; (5) Risk mitigation: special attention to high-impact synthetic content such as deepfakes and impersonation-related media; and (6) Regulatory calibration: delegating technical specifics to implementing regulations that set label formats, metadata schemas and procedural rules. The policy recognizes overlaps with data protection and intellectual property law and affirms that labeling does not remove other legal obligations (for instance consent or processing restrictions for biometric or health-related data).
Implementation Framework
Implementation is structured in two phases: immediate disclosure and labeling obligations upon entry into force, plus a follow-on rulemaking phase where the executive authority will adopt technical standards for label visibility, metadata formats, certification or conformity assessment processes, and the list of justified exceptions. Providers offering services in Peru would be required to add persistent indicators or machine-readable metadata to outputs accessible to users in Peru. The bill contemplates that the implementing regulation will define thresholds (e.g., scale of operations, nature of audience) and create administrative procedures for audits, notices of non-compliance and remediation plans. The implementing authority must coordinate with sectoral regulators (health, finance, telecoms) for sector-specific guidance.
Monitoring and Evaluation
Monitoring includes periodic audits by the competent authority, mandatory reporting by providers on labeling compliance, and mandatory retention of provenance logs for a defined period. Evaluation metrics proposed in parliamentary discussion include rates of labeled content, consumer complaints, detected instances of unlabeled synthetic content, and incidence of harms tied to synthetic media. The bill anticipates mechanisms for technical verification including sampling, forensic analysis, and cooperation with platforms to trace content origin. Public reporting and transparency of enforcement actions are foreseen to create accountability and to inform adjustments to the regime.
Penalties, Liability, and Appeals
Sanctions contemplated in the legislative summaries include administrative fines proportional to the infraction, orders to correct or remove content, temporary suspension of services in cases of repeated or severe violations, and publication of sanctions as a reputational remedy. The draft stresses civil and criminal liability for uses of AI that amount to fraud, defamation or other illegal behavior remains unaffected. Affected providers would have administrative appeal rights and access to judicial review of sanctioning decisions under Peru's administrative law framework.
Relationship to Other Instruments
The bill is designed to operate alongside existing Peruvian laws on personal data protection, consumer protection, telecommunications and intellectual property. It expressly states that labeling obligations do not substitute for informed consent where required under data protection rules and that sectoral regulations (e.g., health or financial services) may impose additional constraints. The initiative has been discussed in parallel with other AI-related bills and national AI strategy workstreams; see congressional committee materials and stakeholder consultations for cross-references to other proposals.
International Alignment
Project 6524/2023 aligns with global and regional efforts to promote transparency for synthetic media and AI systems. The proposal echoes elements present in other jurisdictions' guidance on labeling automated content and the EU's broader work on AI regulatory approaches and digital labeling (for example, debates on digital labeling of products and synthetic media). Peruvian drafters and commentators have referenced comparative practice and international policy trends to ensure compatibility and to facilitate cross-border enforcement where foreign providers serve Peruvian users. See comparative commentary at CMS Peru and legislative discussions hosted by Congress committees.
Implementation Timeline
| Milestone | Indicative date |
|---|---|
| Presentation to Congress | 2023-11-27 |
| Committee review and hearings (initial) | 2024-05 to 2025-02 (committee schedules and hearings) |
| Regulatory drafting period (if enacted) | 0-180 days from enactment (reglamento) |
| Enforcement operational | phased after reglamento adoption (6-12 months) |
Sources and References
| Source | Type |
|---|---|
| Congress communications: "Informan sobre avances en investigación y ciencia en Huánuco" (mentions PL 6524/2023) | Primary Source |
| LP Derecho: "Proponen que quienes usen inteligencia artificial para crear contenido digital deberán informarlo" | Primary Source / Legislative Reporting |
| CMS (TMC Legal bytes): summary of Proyecto de Ley for digital labeling (Nov 2023) | Secondary Analysis |
Requirements for a company
What an organisation has to do under Peru - AI Digital Labeling Bill (6524/2023), at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Not yet in force (Proposed). These requirements apply once the instrument takes effect and may change before then.
Must do
10- Disclose AI involvement in digital content available to users in Peruvian territory.Providers of AI systems creating, manipulating, or interacting with digital content for Peruvian users.
- Label AI-generated or AI-manipulated content.Providers of AI systems generating or manipulating content for Peruvian users.
- Add persistent indicators or machine-readable metadata to AI outputs.Providers offering AI services in Peru.
- Maintain recordkeeping and provenance metadata for generated content.Providers of AI systems generating content.
- Retain provenance logs for a defined period.Providers of AI systems generating content.
- Obtain informed consent where required by data protection rules.Providers of AI systems processing personal data.
- +4 more in the table below
Must not do
0Nothing in this category.
Should do
0Nothing in this category.
Should not do
0Nothing in this category.
Who must do what
The obligations under Peru - AI Digital Labeling Bill (6524/2023), most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Providers of AI systems creating, manipulating, or interacting with digital content for Peruvian users. | Disclose AI involvement in digital content available to users in Peruvian territory. “requiring providers to disclose AI involvement in content available to users in Peruvian territory.” | Upon entry into force | — | Critical |
| 2 | Providers of AI systems generating or manipulating content for Peruvian users. | Label AI-generated or AI-manipulated content. “mandatory labeling of AI-generated or AI-manipulated content” | Upon entry into force | — | Critical |
| 3 | Providers offering AI services in Peru. | Add persistent indicators or machine-readable metadata to AI outputs. “Providers offering services in Peru would be required to add persistent indicators or machine-readable metadata to outputs” | Upon entry into force | — | Critical |
| 4 | Providers of AI systems generating content. | Maintain recordkeeping and provenance metadata for generated content. “recordkeeping and provenance metadata for generated content” | — | — | Critical |
| 5 | Providers of AI systems generating content. | Retain provenance logs for a defined period. “mandatory retention of provenance logs for a defined period.” | — | — | Critical |
| 6 | Providers of AI systems processing personal data. | Obtain informed consent where required by data protection rules. “labeling obligations do not substitute for informed consent where required under data protection rules” | Before processing personal data | — | Critical |
| 7 | Providers of AI systems subject to this regulation. | Maintain compliance documentation and enable audits by the competent authority. “empowered to conduct audits, verify compliance” | — | — | Important |
| 8 | Providers of AI systems subject to this regulation. | Report on labeling compliance to the competent authority. “mandatory reporting by providers on labeling compliance” | — | — | Important |
| 9 | Providers of AI systems subject to this regulation. | Cooperate with technical verification mechanisms to trace content origin. “cooperation with platforms to trace content origin.” | — | — | Important |
| 10 | Providers of AI systems subject to this regulation. | Provide explanatory materials and contact channels in Spanish to consumers. “Consumer information: Provide explanatory materials and contact channels in Spanish” | Upon entry into force | — | Important |
Related Regulations
© Regulations.AI · updated on 13-Jun-2026