Peru - AI Promotion and Regulation (08223)

Project 8223/2023 (08223) — Bill for the promotion and regulation of AI use in Peru

Proyecto 8223/2023 (08223) — Ley de fomento y regulación del uso de la inteligencia artificial

Peru

RAI-PE-NA-P80PAXX-2024
Under Review(Under Review)
BillGovernance and OversightRisk ManagementConformity Assessment and Registration
Export PDF

Project 08223/2023 is a legislative proposal introduced to promote, regulate and establish principles, institutional arrangements and obligations for the development, deployment and use of artificial intelligence (AI) across the Peruvian public and private sectors. The draft emphasizes ethical principles (transparency, non-discrimination, privacy, human oversight), creation of a national AI center, sectoral deployment in public services, and measures to protect fundamental rights while fostering innovation.

Overview

Project 08223/2023 ("Ley de fomento y regulación del uso de la inteligencia artificial en el Perú") is a broad legislative initiative presented to the Peruvian Congress that aims to both promote and regulate artificial intelligence (AI) nationally. Registered on 14 June 2024, the draft positions AI as a public policy priority to modernize public services and accelerate economic development while safeguarding constitutional rights. The bill sets out general objectives (promotion, regulation, protection of rights), a set of guiding principles (transparency, privacy, non-discrimination, security, supervision by humans), and institutional measures including a proposed national technical center to support public entities and consolidate high-performance processing resources. See the parliamentary dossier and text at Congress expediente 8223 and an archived project PDF referenced by legal repositories such as the congressional file server.

Definitions

The bill offers purpose-driven definitions to reduce ambiguity in scope and obligations. Core definitions include: (i) "Artificial Intelligence (AI) system" — electronic-mechanical systems that perform predictions, recommendations or decisions for human-defined objectives; (ii) "developer" and "operator" — entities that design and deploy AI systems; (iii) "high-impact system" — systems whose malfunction or bias could substantially affect individual rights or public interests; and (iv) "personal data" — consistent with existing Peruvian data protection concepts. These definitions aim to align technical concepts with statutory responsibilities for safety, documentation and human oversight.

Governance and Institutional Framework

The draft sets out an institutional architecture for coordination and oversight. It mandates coordination among sectoral ministries (e.g., Health, Education, Justice, Transport), assigns responsibilities to a central coordinating body to implement the national AI strategy, and proposes the creation of a specialized national center to provide shared computing and evaluation services. Public agencies would be required to integrate AI governance into procurement, operations and service delivery, and to report progress to the Congress annually. Several provisions require cooperation with the national data protection authority and cybersecurity agencies to ensure integrated oversight. The bill text and explanatory memorandum describe institutional tasks in detail; see the congressional communications summary at Congress communications and the project PDF on the file server.

Key Focus Areas

The proposal concentrates on several interlinked areas: (1) Ethical/legal principles — enshrining transparency, privacy, non-discrimination, safety, accountability and human oversight as mandatory principles for public and private AI use; (2) Public sector modernization — enabling AI to improve efficiency in education, health, justice and urban mobility while requiring safeguards to protect vulnerable groups; (3) Data governance — promoting secure, lawful data practices and inter-agency data sharing mechanisms with privacy protection; (4) Technical conformity and assessment — establishing evaluation, certification or registration obligations for certain systems, especially those with significant social impact; (5) Risk management — requiring lifecycle risk assessments, testing and documentation (including logs and model cards) and contingency planning; (6) Cybersecurity — mandating security standards for model and data protection and incident response; (7) Education and capacity-building — supporting workforce training, research and public awareness; and (8) Enforcement and remedies — enabling administrative sanctions, corrective measures and pathways for redress. The bill attempts to balance promotion and control by incentivizing innovation (shared resources, national center, public procurement preferences) while conditioning deployment on adherence to safeguards to protect fundamental rights.

Implementation Framework

Implementation is conceived through a hybrid combination of primary law provisions and delegated regulations. The draft sets general obligations and authorizes the executive/ministries to issue technical norms and sector-specific rules for detailed procedures (e.g., conformity assessment protocols, registration forms, labelling and certification). Public procurement rules would be adapted to require risk assessments and compliance statements for AI procured by the State. The national coordinating body and the proposed technical center would publish technical guidelines, establish evaluation labs, and offer centralized compute and algorithmic audit services for smaller public entities, lowering barriers to adoption while standardizing compliance. The bill anticipates phased implementation, with high-impact systems subject to immediate, stricter requirements and other systems subject to progressive compliance schedules.

Monitoring and Evaluation

Monitoring provisions require regular reporting by the coordinating body to Congress, including an annual report on implementation of the national digital transformation and AI strategy. The bill envisages maintaining registries or inventories of deployed AI systems (particularly high-impact ones), requiring periodic audits and post-deployment monitoring, and establishing key performance indicators tied to public-service improvements and rights protections. Independent audits, third-party conformity assessments and public transparency reports are promoted to facilitate external oversight and civil society scrutiny.

Penalties, Liability, and Appeals

The draft contemplates administrative sanctions (fines, suspension of operation, remedial orders) for non-compliance and supports procedural guarantees, including rights to administrative appeal. It recognizes civil liability and redress for harms caused by AI systems, while leaving specific penalty scales, enforcement powers and judicial interplay to implementing rules or complementary legislative instruments. The design seeks to enable effective remedies without unduly chilling legitimate innovation in research and public service delivery.

Relationship to Other Instruments

The bill is written to interact with Peru's existing data protection framework and sectoral laws (health, consumer protection, public procurement, cybersecurity) and anticipates coordination with the national data protection authority and sector regulators. It expressly references the need to be consistent with constitutional guarantees and existing administrative law principles, and it foresees regulatory harmonization where sectoral regulators have pre-existing competences (e.g., medical devices in Health, financial regulators in Finance).

International Alignment

Project 08223/2023 signals intent to align Peru's AI governance with international norms and trends, including risk-based approaches used in other jurisdictions, interoperability of technical standards, and participation in multilateral cooperation for ethical AI. The draft encourages adoption of best practices for model transparency, impact assessments and cybersecurity consistent with international guidance and cooperation frameworks.

Implementation Timeline

MilestoneIndicative Date
Congressional registration of project2024-06-14
Referral to relevant congressional committees2024 (committee stage ongoing)
Committee review and technical hearingsTo be scheduled (subject to congressional calendar)
Promulgation / entry into force (if approved)To be determined — effective date to be set in final law

Compliance Checklist

RequirementApplicable actors
Adopt lifecycle risk assessments and maintain documentation (model cards, logs)Developers, Operators, Public agencies
Register high-impact systems in the national inventory (if required)Operators of high-impact systems
Implement data protection and cybersecurity safeguardsAll entities processing personal data
Provide transparency notices and human oversight mechanismsOperators deploying automated decision-making
Submit annual implementation reports to coordinating body (public entities)Public agencies

Sources and References

SourceType
Proyecto de Ley N.° 08223/2023-CR — Congressional expediente (file server)Primary Source
vLex — Project summary and metadataSecondary / Repository
University of the Andes — regulatory repository summarySecondary / Repository
Plain English

Peru is considering a new law to promote and regulate artificial intelligence (AI) across its public and private sectors, aiming to foster innovation while protecting fundamental rights. This proposed legislation would apply broadly to anyone developing or operating AI systems in Peru, from government agencies to private companies. A key focus is on "high-impact systems"—those whose malfunction or bias could significantly affect individual rights or public interests.

If passed, the law would impose several important obligations. All AI systems must adhere to ethical principles such as transparency, privacy, non-discrimination, safety, accountability, and human oversight. Developers and operators would need to conduct lifecycle risk assessments, maintain thorough documentation (like model cards and logs), and ensure robust data protection and cybersecurity measures are in place. High-impact systems, in particular, will face stricter requirements, potentially including mandatory evaluation, certification, or registration. Public agencies would also be required to integrate AI governance into their procurement, operations, and service delivery, reporting progress annually.

The bill is currently under review in the Peruvian Congress, so its effective date is unknown and would be set in the final law if approved. It anticipates a phased implementation, with high-impact systems facing immediate, stricter rules, while other systems would have progressive compliance schedules. Non-compliance could lead to administrative sanctions, including fines, suspension of operations, and corrective orders. The law also recognizes civil liability and redress for harms caused by AI systems.

A practical pitfall for businesses is the bill's reliance on future delegated regulations for many specifics, such as detailed conformity assessment protocols or registration forms. This means that while the general principles are clear, the exact compliance steps will evolve, requiring ongoing vigilance. The creation of a new national AI center and coordinating body also signals a significant shift in regulatory oversight, centralizing control and support for AI development.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 10 marked complete

Plain-English obligations under Peru - AI Promotion and Regulation (08223). Not legal advice — verify against the official text before relying on it.

  1. #1CriticalBefore placing on market

    Applies to: Developers and operators of AI systems.

    requiring lifecycle risk assessments, testing and documentation (including logs and model cards) and contingency planning
  2. #2CriticalBefore deployment

    Applies to: All entities developing or operating AI systems.

    mandating security standards for model and data protection and incident response
  3. #3CriticalBefore deployment

    Applies to: Developers and operators of AI systems.

    enshrining transparency, privacy, non-discrimination... and human oversight as mandatory principles for public and private AI use
  4. #4CriticalBefore deployment

    Applies to: Operators of high-impact AI systems.

    establishing evaluation, certification or registration obligations for certain systems, especially those with significant social impact
  5. #5CriticalPeriodically

    Applies to: Operators of AI systems.

    requiring periodic audits and post-deployment monitoring
  6. #6Important

    Applies to: Peruvian public agencies.

    Public agencies would be required to integrate AI governance into procurement, operations and service delivery
  7. #7ImportantAnnually

    Applies to: Central coordinating body (on behalf of public agencies).

    Monitoring provisions require regular reporting by the coordinating body to Congress, including an annual report
  8. #8Important

    Applies to: All entities developing or operating AI systems.

    Several provisions require cooperation with the national data protection authority and cybersecurity agencies
  9. #9Important

    Applies to: Peruvian public agencies procuring AI.

    Public procurement rules would be adapted to require risk assessments and compliance statements for AI procured by the State.
  10. #10Recommended

    Applies to: Peruvian public agencies.

    Education and capacity-building — supporting workforce training, research and public awareness

© Regulations.AI — created on 13-Jun-2026