Peru - AI Penal Code Amendments (8746/2024)
Project 8746/2024 — Bill to modify the Penal Code and related provisions regarding AI (consolidated into penal amendments)
Proyecto 8746/2024 — Proyecto de ley que modifica el Código Penal y disposiciones relacionadas sobre la IA (consolidado en enmiendas penales)
Peru
RAI-PE-NA-P8MPCXX-2024Project 8746/2024 (presented to Congress on 29 August 2024) proposes to modify Peru's Penal Code and the Law on Computer Crimes (Ley N.º 30096) to treat the use of artificial intelligence (AI) as an aggravating circumstance in the commission of certain offences (including fraud/estafa and crimes involving manipulated multimedia such as deepfakes). The draft authorises judges to increase custodial penalties (up to one third above the legal maximum) and requires the Executive to issue implementing norms within 60 days of enactment.
Summary
Read full text ↗Plain English
Overview
Project 8746/2024-CR is a parliamentary initiative presented on 29 August 2024 that was consolidated into a Commission of Justice text and included in the dictamen approved by the Plenary in April 2025. The consolidated measure aims to modify the Penal Code (Decreto Legislativo N.º 635) and the Law on Computer Crimes (Ley N.º 30096) to include the use of artificial intelligence as an aggravating circumstance when committing offences, with an express focus on harms such as fraud (estafa), identity appropriation using synthetic voice/image, child sexual exploitation via deepfakes and AI-enabled defamation. See the official Congressional summary of the Plenary approval: Congress press release: "Incluyen como agravante uso de la inteligencia artificial para la comisión de delitos".
Definitions
The draft (as consolidated in the dictamen) uses operational definitions intended for penal application: "artificial intelligence" is understood broadly to include algorithmic systems capable of generating, transforming or synthesizing data or content (including audio, image, video and text), and systems that autonomously process inputs to produce outputs influencing decisions or communications. "Use of AI" for the purposes of the aggravating circumstance covers: (a) generation or transformation of audio/voice, image, video or biometric simulations of a real person; (b) automated deployment of AI to scale or amplify communications for fraudulent or harmful intent; and (c) use of AI to produce or distribute material with sexual, defamatory or illicit content intended to cause harm. The draft also distinguishes between lawful development/academic use and malicious use in commission of crimes; culpability is triggered when AI is knowingly used to facilitate the criminal conduct.
Governance and Institutional Framework
The bill assigns primary legislative changes to the Penal Code and calls for Executive-level instruments to operationalize certain investigative and evidentiary measures. Under the approved dictamen, the Presidency of the Council of Ministers (PCM) together with the Ministry of Justice and Human Rights (MINJUSDH) are tasked to issue complementary regulation within 60 calendar days to enable application of the new aggravating circumstance and coordination among prosecutorial, forensic and regulatory bodies. See the Plenary debate and the explicit delegation for rulemaking in the Congressional record: Diario de Debates (Plenary debate and approved text). Operational responsibilities implied in the dictamen include: (i) prosecutors and the Public Ministry (Ministerio Público) to adapt investigative protocols; (ii) MINJUSDH and the Autoridad Nacional de Protección de Datos Personales (ANPD) to ensure data-protection compliance where personal data or biometric identifiers are involved; and (iii) judicial training for assessment of synthetic evidence.
Key Focus Areas
The consolidated text concentrates on the following substantive issues: (1) Penal aggravation — introducing an aggravating circumstance where AI is used to commit an offence and authorizing judges to increase custodial penalties (the public summary indicates up to one third above the statutory maximum for the underlying offence); (2) Estafa (fraud) — addition of an explicit numeral to Article 196-A (estafa) targeting impersonation via AI-produced voice/image and establishing aggravated custodial ranges in draft texts (earlier drafts referenced 4–8 years and a pecuniary sanction expressed as days-multa for particularly severe AI-based fraud); (3) Sexual exploitation and image-based abuse — coverage of AI-generated child sexual content and sexualized deepfakes as aggravating; (4) Intellectual-property and identity harms — seeking alignment between criminal law and rights-protection regimes; and (5) Coordinated enforcement and technical capability building — mandates for regulation, evidence-preservation and institutional cooperation. The dictamen deliberately frames its amendments as targeted aggravators rather than broad prohibitions on AI development, to reduce risks of chilling innovation while strengthening sanctions against harmful uses of the technology.
Implementation Framework
Implementation requires a mix of legal, operational and technical steps: (a) the Executive is to adopt implementing norms within 60 days to define procedures for evidence preservation, chain-of-custody of digital assets and inter-institutional cooperation (public summary referenced at the time of Plenary approval); (b) the Public Ministry must adapt prosecutorial guidelines to document AI use and causation (e.g., linking a synthetic artifact to a specific perpetrator or campaign); (c) law-enforcement and forensic units should acquire or contract forensic tools for provenance analysis of multimedia and metadata preservation; and (d) the ANPD (within MINJUSDH) must reconcile data-protection obligations where datasets or biometric inputs were processed to generate synthetic content. The approved dictamen contemplates training for judges and prosecutors to assess AI-generated evidence and suggests judicial discretion in sentencing where AI materially increased harm or sophistication.
Monitoring and Evaluation
The dictamen does not create a new supervisory agency but requires existing institutions to report on application and impact. The implementation regulation to be issued by the PCM and MINJUSDH was expected to set reporting schedules and assign responsibility for monitoring rates of invocation of the aggravating circumstance, convictions, recidivism and identified harms connected to AI-mediated offences. Monitoring metrics would include: number of investigations citing AI use, conviction rates, average sentence increases when aggravation is applied, and instances of cross-border evidentiary cooperation. The absence of a dedicated AI oversight body in the text means evaluation will rely on periodic inter-agency reporting and analysis by the Ministry of Justice and Congress's oversight mechanisms.
Penalties, Liability, and Appeals
The principal express measure is a sentencing aggravator: where AI is used to facilitate or commit an offence, the judge may increase the custodial sentence up to one third above the legal maximum for the base offence. For estafa, earlier draft language referenced in committee materials proposed specific custodial ranges for aggravated cases (commonly cited as four to eight years and a pecuniary sanction in days-multa). The bill leaves intact the ordinary grounds for appeal and judicial review; defendants retain rights to challenge evidentiary linkages between AI artifacts and the accused. The draft places emphasis on proportionality in sentencing while enabling tougher penalties where AI materially enabled scale, deception or harm. Questions remain regarding attribution standards and whether persons who supply models, data or compute without direct intent would be exposed to criminal liability — the dictamen is focused on active, knowing use in the commission of crimes rather than mere development or distribution of neutral tools.
Relationship to Other Instruments
The proposal explicitly amends the Penal Code and Ley N.º 30096 (Law on Computer Crimes) and references obligations under Peru's data-protection framework (Ley N.º 29733 and its regulatory instruments administered by MINJUSDH/ANPD). It complements other legislative activity addressing AI-adjacent risks (e.g., IP, child protection, cybercrime) and relies on executive regulation and existing criminal-procedural law for implementation. It does not purport to replace specialized regulatory frameworks for AI governance (e.g., sectoral policies) but integrates AI-related harms into the criminal law sphere as aggravating factors.
International Alignment
Project 8746/2024 is consistent with an international trend to adapt penal frameworks to AI-enabled harms. While Peru's approach is narrower than comprehensive regulatory models (such as the EU's AI Act that uses a risk-tiered regulatory architecture), the bill follows other jurisdictions' moves to create specific offences or aggravators addressing deepfakes, identity fraud and sexual exploitation that rely on synthetic media. The consolidated dictamen places emphasis on cooperation with international partners for evidence and cross-border investigations, and anticipates the need to align forensic standards with global best practices. Relevant comparative work includes jurisprudence and statutes addressing deepfakes, platform notice-and-takedown procedures, and mutual legal assistance treaties (MLATs) for digital evidence preservation.
Implementation Timeline
| Event | Date |
|---|---|
| Project presented (registered in Congress) | 2024-08-29 |
| Commission of Justice: dictamen approved (session) | 2025-04-09 |
| Plenary approval of consolidated dictamen | 2025-04-16 |
| Executive to issue implementing norms (per dictamen: 60 days after entry into force) | 60 days after enactment (to be set) |
| Expected initial monitoring report (inter-agency) | 6–12 months after regulation |
Compliance Checklist
| Requirement | Who | Notes |
|---|---|---|
| Document and preserve digital evidence linking AI outputs to perpetrators | Public Ministry / Law enforcement | Preserve metadata, model provenance and data access logs |
| Assess data-protection impact where personal data used to create synthetic media | Data controllers / ANPD | Comply with Ley N.º 29733 and implement safeguards |
| Coordinate cross-border evidence requests | Public Ministry / Ministry of Foreign Affairs | Use MLATs or international cooperation tools |
| Train judges and prosecutors on AI forensic evidence | Judicial Branch / Public Ministry | Technical training recommended |
Sources and References
| Source | Type |
|---|---|
| Congreso de la República — "Incluyen como agravante uso de la inteligencia artificial para la comisión de delitos" (press release) | Primary Source |
| Diario de Debates — Plenary session reporting approval of the dictamen (9–16 April 2025) | Primary Source |
| LP Derecho — coverage and draft text summary (Project 8746/2024-CR) | Secondary analysis |
| vLex — copy of the consolidated dictamen document (projects 6573/2023, 7072/2023, 8746/2024, 10525/2024) | Primary Source (document repository) |
| Ley N.º 30096 — Law on Computer Crimes (reference text) | Primary statutory reference |
Peru has adopted a new law that modifies its Penal Code and Computer Crimes Law, making the use of artificial intelligence (AI) an aggravating factor when committing certain offenses, leading to harsher penalties for individuals involved in such crimes.
This legislation applies to anyone who knowingly uses AI to facilitate criminal conduct. The law defines AI broadly, covering algorithmic systems that generate, transform, or synthesize data or content like audio, images, video, and text, or systems that autonomously process inputs to influence decisions. "Use of AI" specifically includes generating or transforming simulations of real people, automating AI to scale fraudulent communications, or producing and distributing illicit content with harmful intent. It’s important to note that the law targets malicious use, not lawful development or academic research.
The most significant impact is that judges can increase prison sentences by up to one-third above the legal maximum for the underlying crime if AI was used. This applies to offenses such as fraud (estafa), identity theft using synthetic voice or image, child sexual exploitation via deepfakes, and AI-enabled defamation. For example, earlier proposals for AI-based fraud suggested sentences of four to eight years.
While the bill has been approved by Congress in April 2025, its exact effective date is still unknown. The Executive branch, specifically the Presidency of the Council of Ministers and the Ministry of Justice and Human Rights, is required to issue detailed implementing regulations within 60 days of the law officially entering into force. These rules will cover investigative procedures, evidence preservation, and coordination among authorities.
A practical pitfall for product managers and founders is the broad definition of AI. While the law focuses on "active, knowing use" in crimes, and not on the mere development or distribution of neutral AI tools, the expansive definition means that many automated systems could potentially fall under its scope if misused. This could lead to questions about attribution standards for those who supply models or data without direct criminal intent.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 8 marked completePlain-English obligations under Peru - AI Penal Code Amendments (8746/2024). Not legal advice — verify against the official text before relying on it.
- #1Critical⏰ 60 days after enactment
Applies to: Presidency of the Council of Ministers and Ministry of Justice and Human Rights
“the Presidency of the Council of Ministers (PCM) together with the Ministry of Justice and Human Rights (MINJUSDH) are tasked to issue complementary regulation within 60 calendar days”
- #2Important
Applies to: Public Ministry (prosecutors)
“prosecutors and the Public Ministry (Ministerio Público) to adapt investigative protocols”
- #3Important
Applies to: Public Ministry and Law enforcement
“the Executive is to adopt implementing norms within 60 days to define procedures for evidence preservation, chain-of-custody of digital assets”
- #4Important
Applies to: Law enforcement and forensic units
“law-enforcement and forensic units should acquire or contract forensic tools for provenance analysis of multimedia and metadata preservation”
- #5Important
Applies to: Autoridad Nacional de Protección de Datos Personales (ANPD)
“the ANPD (within MINJUSDH) must reconcile data-protection obligations where datasets or biometric inputs were processed to generate synthetic content.”
- #6Important
Applies to: Public Ministry and Ministry of Foreign Affairs
“The consolidated dictamen places emphasis on cooperation with international partners for evidence and cross-border investigations”
- #7Important⏰ 6–12 months after regulation
Applies to: Existing institutions involved in enforcement
“The dictamen does not create a new supervisory agency but requires existing institutions to report on application and impact.”
- #8Recommended
Applies to: Judicial Branch and Public Ministry
“The approved dictamen contemplates training for judges and prosecutors to assess AI-generated evidence”
Related Regulations
Project 10525/2024 — Bill to modify the Penal Code and related provisions regarding AI (consolidated into penal amendments)
Peru97% similar
Project 6573/2023 — Bill to modify the Penal Code to include AI usage as an aggravating factor (one of the bills consolidated into later penal amendments)
Peru96% similar
Law No. 32314 — Amendment to the Penal Code and the Law on Computer Crimes to include the use of Artificial Intelligence as an aggravating circumstance (Law that aggravates penalties for crimes committed using AI)
Peru95% similar
Project 7033/2023 (07033) — Bill that proposes to regulate the development and use of Artificial Intelligence in Peru
Peru92% similar
Proyecto de Ley (Boletín 16021-07) — AI-use aggravating circumstance
Chile91% similar
© Regulations.AI — created on 13-Jun-2026