Peru - AI Regulation Bill (07033/2023)

Project 7033/2023 (07033) — Bill that proposes to regulate the development and use of Artificial Intelligence in Peru

Proyecto 7033/2023 (07033) — Proyecto de ley que propone regular el desarrollo y uso de la Inteligencia Artificial en Perú

Peru

RAI-PE-NA-P70TPXX-2024
Under Review(Under Review)
BillGovernance and OversightRisk ManagementConformity Assessment and Registration
Export PDF

Project 7033/2023-CR is a congressional bill presented by Congressman Carlos Javier Zeballos Madariaga that seeks to establish a national legal framework to regulate the development, deployment and use of artificial intelligence (AI) in Peru. The draft advances a risk-based approach with obligations on transparency, data protection, human oversight, conformity assessment and sanctions for non-compliance while aligning with existing national instruments such as Law No. 31814 (promotion of AI) and Peru's data protection regime (Law No. 29733).

Summary

Project 7033/2023-CR, presented in February 2024 by Congressman Carlos Javier Zeballos Madariaga (Podemos Perú), proposes a comprehensive statute to regulate the development and use of artificial intelligence in Peru. The bill aims to create a national legal framework that balances the promotion of innovation and economic development with protection of fundamental rights, privacy and public safety. Core objectives include: (a) defining AI and scope of covered systems; (b) establishing governance structures and institutional competences for oversight; (c) adopting a risk-based classification of AI uses and systems; (d) imposing obligations for transparency, documentation, human oversight, safety testing and cybersecurity; (e) requiring conformity assessment and registration for high-risk AI systems; and (f) detailing enforcement mechanisms, sanctions and civil liability.

The proposal sits alongside Law No. 31814 (the national law that promotes use of AI) and the Peruvian data protection framework (Law No. 29733 and related instruments). The bill constructs obligations applicable to natural and legal persons that develop, provide, operate or deploy AI systems in Peru or target Peruvian users, irrespective of server location — a territorial-and-effects approach common in modern AI legislation. High-level duties anticipated in the draft include conducting algorithmic impact assessments (AIAs) for high-risk uses; implementing technical and organisational measures for data protection and model security; documenting model design, training data provenance, validation and testing records; maintaining auditable logs and traceability; and disclosing meaningful information to affected individuals (explainability and source labelling for synthetic content).

Project 7033/2023 follows a risk-based methodology: it establishes heavier compliance burdens for AI systems that present significant risks to fundamental rights (e.g., automated decision-making producing legal or similarly significant effects, biometric identification, critical infrastructure control). The bill also contemplates prohibitions or express limits on specific uses deemed unacceptable — for example, certain forms of mass surveillance or autonomous systems with lethal effect — while leaving room for sectoral regulation (health, finance, public administration). Oversight and enforcement are assigned to a combination of executive bodies (the draft refers to roles for technical authorities and may interact with the Presidency of the Council of Ministers and sectoral regulators) and existing supervisory regulators for data protection (the Ministry of Justice's Autoridad Nacional de Protección de Datos Personales) and safety/security.

The bill has proceeded through committee stages but has faced procedural actions: the text was presented around 13 February 2024 and has been discussed in committee sessions; a later dictamen by the Commission of Budget and Account General of the Republic recorded an inhibition of the draft in April 2025 (a procedural outcome that can pause or re-route the bill for further consideration). Primary public information about the initiative is available in official Congressional communications and the public legislative file for expediente 7033. Analysts and law firms have described the draft as consistent with a regional trend toward risk-based AI laws and emphasize interoperability with Law 31814 and Peru's PDP law (Law No. 29733). Sources: official Congressional communications, government publications on Law 31814 regulation, and Ministry of Justice materials on data protection.

Full article

Read full text ↗

Overview

Project 7033/2023-CR — "Law that regulates the development and use of Artificial Intelligence in Peru" — was presented to Congress in February 2024 by Congressman Carlos Javier Zeballos Madariaga (Podemos Perú). The draft seeks to establish a horizontal, risk-based legal regime to govern AI across public and private sectors, prioritizing protection of fundamental rights, privacy and security while fostering innovation and economic development. The initiative is intended to operate in tandem with the existing promotion law (Law No. 31814) and Peru's personal data protection framework (Law No. 29733): it builds obligations for transparency, human oversight, conformity assessment and registration of high-risk systems, and contemplates sanctions for non-compliance. Lead public information sources include official congressional communications and the public expediente for the project; readers can consult the legislative dossier and committee notices for the full proposal and its procedural history. For the bill text and dossier see Congressional expediente 7033 (project text and attachments) and the congressional press release summarizing the bill's presentation and committee discussion at Congress communications (March 11, 2024).

Definitions

The draft provides working definitions for key terms to delimit application and obligations: "artificial intelligence" (systems that, by design, use algorithms, statistical models or machine learning to perform tasks with varying degrees of autonomy), "AI system", "developer", "provider"/"operator", "user", "high-risk AI system", "automated decision making with legal or similarly significant effects", "biometric identification" and "data controller/processor" as linked to existing data protection law. These definitions are structured to ensure that obligations apply not only to on‑shore providers but also to off‑shore actors that offer AI services to persons in Peru or whose systems have demonstrable effects on Peruvian rights and interests. The bill aligns definitional scope to enable interoperation with Law No. 31814 and the national data protection framework (Law No. 29733), thus clarifying overlaps and signalling responsibilities for personal data processing in AI contexts.

Governance and Institutional Framework

Project 7033 envisages a multi‑layered governance model combining legislative oversight, sectoral regulators and a central coordinating technical authority. While the bill's detailed institutional architecture is designed to be consistent with the executive's existing AI governance (notably the role attributed to the Presidency of the Council of Ministers under Law No. 31814), it also contemplates specialized units within sectoral agencies (health, finance, transport) responsible for sectoral risk criteria, certification and market surveillance. The draft assigns responsibilities for: (i) producing norms and guidance for AI risk assessment; (ii) maintaining a national registry of high‑risk systems; (iii) supervising conformity assessment and market surveillance; and (iv) coordinating with the Autoridad Nacional de Protección de Datos Personales (ANPD) — the Ministry of Justice authority in charge of data protection — for cross-cutting privacy oversight. See the executive/regulatory context in the publication of the Law 31814 regulation process published by the PCM at PCM / El Peruano project regulation notice and ANPD guidance at Ministry of Justice / ANPD (data protection notices).

Key Focus Areas

The draft organizes obligations and prohibitions around several principal axes: risk classification; transparency and disclosure; data protection and privacy; safety testing and validation; cybersecurity and model robustness; human oversight and redress; conformity assessment/registration; accountability, documentation and auditability; and enforcement including administrative sanctions and civil liability. Under the risk-based approach, lower‑risk AI tools are subject to minimal governance (best practices and notice obligations), whereas high‑risk systems — those that materially affect fundamental rights, access to public services, legal status or core economic entitlements — trigger mandatory impact assessments, pre-market conformity checks and registration in a public registry. The bill also contemplates special rules for sensitive categories (biometric identification, credit scoring, health diagnostics, employment decisions and public-sector adjudications). It requires that developers and deployers ensure data provenance, labelling of synthetic content, robust incident reporting and technical measures to prevent model inversion or illicit re‑identification. These focus areas reflect the national effort to balance innovation (as emphasised in Law No. 31814) with rights protection and public safety; for contextual coverage of the national policy trajectory see analysis at Sistemas de Algoritmos Públicos (Univ. de los Andes) – Peru dossier.

Implementation Framework

Implementation in the draft is staged and assigns responsibilities to three broad actors: (1) providers/developers/operators who must perform risk classification, AI impact assessments (AIAs), security testing, documentation and reporting; (2) sectoral regulators who shall develop technical standards and conformity procedures for critical domains; and (3) a central coordination body (to be defined in secondary regulation) that will maintain the national registry, publish guidance, coordinate cross‑sector supervision and manage public transparency portals. The draft contemplates delegated rule‑making power for the Executive (to issue technical rules and enforceable standards) in order to keep pace with technological change. Implementation tools include mandatory pre‑deployment testing for high‑risk models, periodic audits, third‑party conformity assessment bodies and public incident registries for harms affecting large numbers of persons. For practical context on interaction with executive regulation, see the PCM notice on the Law 31814 regulatory process at PCM / El Peruano.

Monitoring and Evaluation

The bill establishes monitoring lines including periodic reporting by providers (incident reports, impact-monitoring summaries), audit rights for supervisory authorities, and public transparency measures (registry entries, summary AIAs). It defines performance indicators for supervision: number of registered high‑risk systems, sanctions issued, incidents reported, and remediation timeliness. The draft also envisages periodic reviews of regulatory scope and technical annexes (risk lists and thresholds) to be updated through stakeholder consultations. Monitoring will combine active market surveillance by regulators and a citizen-facing channel for complaints and harm reports. This approach aligns with international good practice that couples proactive conformity assessment with reactive market surveillance and citizen redress channels.

Penalties, Liability, and Appeals

Project 7033 sets out an enforcement ladder where regulatory authorities can impose: corrective orders (remediation plans, disclosure mandates), temporary suspensions of AI system operation, administrative fines proportional to harm and economic capacity, and referral for civil or criminal proceedings where existing penal statutes are implicated. The bill provides for civil liability through private causes of action (compensation for material and immaterial harm) and preserves judicial appeal routes against administrative measures. To ensure due process, the bill incorporates contestation procedures and administrative review timelines. The draft also contemplates increased penalties for repeat offences and for systems that intentionally circumvent safeguards. These mechanisms are designed to work with the ANPD's sanctioning powers under Law No. 29733 for data protection breaches.

Relationship to Other Instruments

Project 7033 explicitly situates itself relative to key national instruments: (i) Law No. 31814 (the law that promotes the use of AI), whose regulation and governance tasks were allocated to the Presidency of the Council of Ministers and technical secretariats (see DS / PCM regulatory notice); and (ii) Law No. 29733 (Personal Data Protection), where the Ministry of Justice and its ANPD retain authority over data privacy matters and sanctioning powers (see ANPD materials at Minjus / ANPD). The draft aims to fill regulatory gaps by providing horizontal, cross‑sector obligations while deferring technical standards and procedural rules to delegated regulation and sectoral authorities.

International Alignment

The bill adopts a risk‑based, rights‑protecting architecture that aligns with international initiatives and emerging regional practice (EU AI Act influence, OECD recommendations, and regional Latin American bills). Its territorial/effects scope, emphasis on impact assessment, mandatory documentation and conformity assessment mirror elements in other advanced proposals worldwide; the draft is intended to enable interoperability with international standards and to facilitate cross‑border cooperation on market surveillance and incident response. Peru's existing policy trajectory under Law 31814 and PCM coordination provides a ready mechanism for international engagement and regulatory convergence.

Implementation Timeline

MilestoneTarget Date (example/procedural)
Presentation to Congress2024-02-13 (public presentation and committee referral)
Committee review and public hearings2024 (through 2025 - multiple sessions and technical mesas)
Commission dictamen / procedural action2025-04-01 (dictamen recorded; inhibition by Budget Commission)
Executive drafting of technical regulation (if approved)To be set by delegated authority (e.g., PCM / SGTD) — typically 90–180 days after enactment
Phased compliance windows for high‑risk systems6–18 months after secondary regulation publication (staggered by sector and entity size)

Sources and References

SourceType
Congressional expediente 7033/2023-CR (project text and attachments)Primary Source
Congress communications: summary of presentation and committee discussion (March 11, 2024)Primary Source
Dictamen recaído en el proyecto 07033/2023-CR (committee dictamen documentation)Secondary / Official Record
PCM / El Peruano: publication and regulation process for Law No. 31814 (AI promotion law)Primary Source (Official Gazette notice)
Ministry of Justice / ANPD: data protection notices and powers (context on Law No. 29733 enforcement)Primary Source (Government)

Requirements for a company

What an organisation has to do under Peru - AI Regulation Bill (07033/2023), at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Not yet in force (Under Review). These requirements apply once the instrument takes effect and may change before then.

Must do

12
  • Classify your AI system's risk level.Developers and operators of AI systems.
  • Conduct a mandatory Algorithmic Impact Assessment for high-risk AI systems.Providers of high-risk AI systems.
  • Perform pre-market conformity checks for high-risk AI systems.Providers of high-risk AI systems.
  • Register high-risk AI systems in the national registry.Providers and operators of high-risk AI systems.
  • Comply with Peru's personal data protection framework (Law No. 29733).All actors processing personal data with AI systems.
  • Conduct security testing and adversarial robustness checks for AI systems.Developers and operators of AI systems.
  • +6 more in the table below

Must not do

0

Nothing in this category.

Should do

0

Nothing in this category.

Should not do

0

Nothing in this category.

Who must do what

The obligations under Peru - AI Regulation Bill (07033/2023), most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Developers and operators of AI systems.Classify your AI system's risk level.
providers/developers/operators who must perform risk classification
Before placing on marketCritical
2Providers of high-risk AI systems.Conduct a mandatory Algorithmic Impact Assessment for high-risk AI systems.
high‑risk systems [...] trigger mandatory impact assessments
Before placing on marketCritical
3Providers of high-risk AI systems.Perform pre-market conformity checks for high-risk AI systems.
high‑risk systems [...] trigger [...] pre-market conformity checks
Before placing on marketCritical
4Providers and operators of high-risk AI systems.Register high-risk AI systems in the national registry.
high‑risk systems [...] trigger [...] registration in a public registry.
Before placing on marketCritical
5All actors processing personal data with AI systems.Comply with Peru's personal data protection framework (Law No. 29733).
aligning with existing national instruments such as [...] Peru's data protection regime (Law No. 29733).
Critical
6Developers and operators of AI systems.Conduct security testing and adversarial robustness checks for AI systems.
providers/developers/operators who must perform [...] security testing
Before placing on marketCritical
7Providers and operators of AI systems.Report incidents rapidly to the regulator and affected individuals when required.
requires that developers and deployers ensure [...] robust incident reporting
Rapid notificationCritical
8Developers and deployers of AI systems.Ensure data provenance and label synthetic content generated by AI systems.
requires that developers and deployers ensure data provenance, labelling of synthetic content
Before placing on marketImportant
9Providers of AI systems.Maintain comprehensive documentation and audit logs for AI systems.
providers/developers/operators who must perform [...] documentation and reporting
Important
10Providers and operators of AI systems.Implement measures for human oversight and provide redress mechanisms for affected individuals.
builds obligations for transparency, human oversight, conformity assessment
Important
11Providers of lower-risk AI tools.Provide notice for lower-risk AI tools.
lower‑risk AI tools are subject to minimal governance (best practices and notice obligations)
Before placing on marketImportant
12Providers of AI systems.Cooperate with periodic audits conducted by supervisory authorities.
Implementation tools include [...] periodic audits
Important

© Regulations.AI · updated on 13-Jun-2026