Peru - AI Regulatory Framework (Law No. 31814)
Peru AI Regulation Overview
Peru
RAI-PE-NA-SUMMARY-2026Peru's AI landscape is governed by a risk-based framework under Law No. 31814 and specialized criminal provisions in Law No. 32314. Oversight is centralized within the Presidency of the Council of Ministers, focusing on ethical deployment, transparency, and the protection of fundamental rights.
Full article
Overview
Peru's strategic approach to artificial intelligence is deeply rooted in its broader National Digital Transformation System (SNTD), which was established to centralize and harmonize the country's digital evolution. The journey began in earnest with the enactment of Decree-Law No. 1412, the Digital Government Law, which established the legal foundations for digital identity, interoperability, and the use of emerging technologies in public administration. This was followed by the National Policy for Digital Transformation to 2030, a landmark document that identified AI as a transformative force capable of addressing systemic inefficiencies in the Peruvian economy. Law No. 31814, passed in 2023, represents the formalization of these aspirations into a concrete regulatory framework. This law does not merely encourage AI adoption; it mandates that such adoption occur within a framework of ethical responsibility, transparency, and human-centricity. By centralizing authority within the Presidency of the Council of Ministers (PCM), Peru has ensured that AI policy is not siloed within individual ministries but is instead treated as a cross-cutting national priority. This centralized model allows for a more cohesive response to the rapid advancements in generative AI and large language models, ensuring that the state can pivot its regulatory stance as the technology evolves. The framework also emphasizes the importance of digital talent, recognizing that a robust regulatory environment must be matched by a workforce capable of developing and managing these complex systems.
Regulatory Approach
The Peruvian regulatory philosophy is defined by a sophisticated risk-based classification system, formalized in Supreme Decree No. 115-2025-PCM. This system categorizes AI applications into three distinct tiers: prohibited, high-risk, and acceptable risk. Prohibited AI systems are those that pose an existential or unacceptable threat to fundamental rights, such as systems designed for subliminal manipulation that results in physical or psychological harm, or mass surveillance systems that lack a specific legal mandate and judicial oversight. High-risk systems, which include AI used in critical infrastructure management, educational assessment, recruitment, and credit scoring, are subject to a rigorous compliance regime. Developers and users of high-risk AI must conduct mandatory Algorithmic Impact Assessments (AIA), maintain detailed technical documentation, and ensure that a human remains "in the loop" to oversee automated decisions. This risk-based approach is designed to be dynamic, allowing the SGTD to update the list of high-risk applications as new use cases emerge. Acceptable risk systems, which comprise the majority of AI applications like spam filters or video game AI, are subject to minimal transparency requirements, primarily focused on informing the user that they are interacting with an AI. This nuanced approach ensures that Peru remains a competitive destination for tech investment while providing a safety net that protects its citizens from the most egregious potential abuses of algorithmic power.
Key AI Legislation
The legislative landscape is anchored by Law No. 31814, which serves as the "organic law" for AI in Peru. This statute is supported by a suite of implementing regulations and specialized acts. Supreme Decree No. 115-2025-PCM provides the technical granularity needed to enforce Law 31814, defining the specific parameters for risk assessment and the administrative duties of the Secretariat of Government and Digital Transformation (SGTD). In the realm of criminal law, Law No. 32314 represents a pioneering effort to modernize the Penal Code for the digital age. By making the use of AI an aggravating circumstance in a wide range of crimes—from fraud to sexual exploitation—Peru has sent a clear message that technology will not serve as a shield for criminal activity. Furthermore, Law No. 32082 and its regulation (DS 015-2025-RE) demonstrate how AI is being integrated into specific state functions, such as consular services, where automated systems are now used to streamline document processing and citizen assistance abroad. Other foundational laws, such as the Digital Government Law (DL 1412) and the Law on Personal Data Protection (Law 29733), provide the necessary infrastructure for data governance and security. These laws collectively form a multi-layered defense against technological risk while providing a clear roadmap for legitimate innovation.
Governance & Enforcement Bodies
The Presidency of the Council of Ministers (PCM) sits at the apex of Peru's AI governance structure. Within the PCM, the Secretariat of Government and Digital Transformation (SGTD) functions as the national technical-normative authority. The SGTD's role is multifaceted: it issues technical guidelines, maintains the National Registry of High-Risk AI Systems, and coordinates the implementation of the National AI Strategy (ENIA). This centralization is critical for ensuring interoperability across the public sector, preventing a fragmented landscape where different agencies use incompatible or insecure AI tools. Supporting the SGTD is the National Data Protection Authority (ANPDP), which ensures that AI systems comply with the Law on Personal Data Protection (Law No. 29733). The ANPDP has the power to audit algorithms to detect bias or unauthorized data processing. Additionally, the National Center for Strategic Planning (CEPLAN) and the National Council for Science, Technology and Technological Innovation (CONCYTEC) provide long-term strategic guidance and support for AI research and development, ensuring that the regulatory framework remains aligned with the country's broader socio-economic goals. The interaction between these bodies creates a checks-and-balances system where innovation is promoted by the SGTD but scrutinized by the ANPDP and the judiciary.
Penalties & Enforcement
Enforcement of AI regulations in Peru is divided into administrative and criminal tracks. Administratively, the SGTD has the authority to monitor compliance with the risk-based framework established by DS 115-2025-PCM. Public and private entities that fail to register high-risk systems or neglect mandatory impact assessments can face administrative sanctions, including fines and the suspension of AI operations. These sanctions are governed by the General Administrative Procedure Law (Law No. 27444), ensuring due process for all parties. On the criminal side, Law No. 32314 has introduced a significant deterrent by amending the Penal Code. When AI is used to facilitate a crime, such as creating deepfakes for extortion or using automated bots for large-scale fraud, the court is required to increase the base sentence by up to one-third. This "AI Aggravator" is one of the first of its kind globally and reflects Peru's commitment to protecting its citizens from the unique harms of synthetic media and algorithmic deception. The Public Prosecutor's Office and the National Police's specialized cybercrime units are tasked with investigating these offenses, utilizing new digital evidence standards to track the origin and deployment of malicious AI. The judiciary also plays a role in reviewing administrative appeals, ensuring that the SGTD's enforcement actions are proportionate and legally sound.
Data Protection Framework
The intersection of AI and data privacy is governed by the Law on Personal Data Protection (Law No. 29733) and its 2025 updates. The Peruvian framework is built on the principle that personal data is a fundamental right, and its processing by AI systems must be transparent, secure, and limited to a specific, legitimate purpose. The ANPDP requires that AI developers implement "privacy by design" and "privacy by default" principles. For systems that process sensitive data, such as biometric or health information, developers must conduct a Data Protection Impact Assessment (DPIA) in addition to the standard AI risk assessment. The 2025 AI Regulation further clarifies that individuals have the right to an explanation of automated decisions that significantly affect them, aligning Peru with the "right to explanation" found in the GDPR. Furthermore, the Digital Government Law (DL 1412) mandates strict security protocols for data stored in the National Data Center, ensuring that AI systems used by the state are protected against cyberattacks and data breaches. The ANPDP also issues specific guidelines for the use of AI in profiling and automated decision-making, ensuring that these practices do not lead to systemic discrimination or the erosion of individual autonomy.
Sector-Specific Rules
Peru has adopted a hybrid approach that combines horizontal AI laws with sector-specific mandates. The most prominent example is the consular sector, where Law No. 32082 authorizes the Ministry of Foreign Affairs to use AI for 24/7 automated citizen services. These rules specify that while AI can handle routine inquiries and document verification, any decision that impacts a citizen's legal rights must be reviewed by a human consular officer. In the education sector, the Ministry of Education (MINEDU) is developing guidelines for the ethical use of generative AI in classrooms, focusing on protecting the data of minors and ensuring that AI tools are used to enhance, rather than replace, pedagogical interaction. In the financial sector, the Superintendency of Banking, Insurance, and AFPs (SBS) is monitoring the use of AI in credit scoring and fraud detection, ensuring that algorithmic models do not result in discriminatory lending practices. In the realm of public safety, the Ministry of the Interior is exploring the use of AI for predictive policing and facial recognition, though these applications are subject to the strict "high-risk" requirements of the 2025 Regulation. These sectoral rules are designed to address the unique technical and ethical challenges of different industries while remaining anchored in the national risk-based framework overseen by the SGTD.
International Alignment
Peru's AI strategy is explicitly designed to align with international standards, particularly those of the OECD and the European Union. As a candidate for OECD accession, Peru has integrated the OECD Recommendation on Artificial Intelligence into its national principles, emphasizing transparency, accountability, and the promotion of digital talent. The risk-based classification system in DS 115-2025-PCM is heavily influenced by the EU AI Act, providing a familiar regulatory environment for international technology companies. Peru is also an active participant in UNESCO's Recommendation on the Ethics of Artificial Intelligence, focusing on the social and cultural impacts of technology. Regionally, Peru plays a leading role in the eLAC (Digital Agenda for Latin America and the Caribbean) and the Andean Community (CAN), advocating for harmonized AI standards that facilitate cross-border data flows and collaborative innovation. This internationalist outlook is intended to position Peru as a regional hub for ethical AI development, attracting foreign investment while ensuring that domestic regulations are robust enough to withstand global technological shifts. Peru also participates in the Global Partnership on AI (GPAI), contributing to international research on AI safety and governance.
Future Developments
The next two years will be a period of intense technical implementation for Peru's AI framework. A primary focus will be the operationalization of "Regulatory Sandboxes," as envisioned in the National AI Strategy. These sandboxes will allow startups and researchers to test high-risk AI applications in a controlled environment under the supervision of the SGTD and ANPDP, fostering innovation while mitigating potential harms. In the legislative sphere, Project 10717/2024 is expected to formalize the integration of AI pedagogy into the national school curriculum, while Project 6524/2023 aims to introduce mandatory "Digital Labeling" for all AI-generated content. This labeling requirement would serve as a critical tool in the fight against disinformation and deepfakes. Additionally, the SGTD is expected to issue a series of Technical Standards (NTP) based on ISO/IEC 42001, providing a clear certification path for companies that want to demonstrate their commitment to AI management excellence. The government is also planning to launch a National AI Observatory to monitor the socio-economic impact of AI and provide real-time data for policy adjustments. These developments signal that Peru is moving beyond the creation of primary laws toward a mature ecosystem of technical standards, specialized oversight, and proactive innovation support.
Key Regulations
| Title | Type | Status | Year |
|---|---|---|---|
| Law No. 31814 — Law that promotes the use of Artificial Intelligence | Act | In Force | 2023 |
| Supreme Decree No. 115-2025-PCM — Regulation of Law No. 31814 | Decree | In Force | 2025 |
| Law No. 32314 — Amendment to the Penal Code (AI Aggravating Circumstance) | Act | In Force | 2025 |
| Law No. 32082 — Digital Transformation in Consular Offices | Act | In Force | 2024 |
| Decree Supreme No. 015-2025-RE — Regulation of Law No. 32082 | Decree | In Force | 2025 |
| National Policy for Digital Transformation to 2030 | Policy | In Force | 2023 |
| Decree-Law No. 1412 — Law Approving the Digital Government | Act | In Force | 2018 |
| Project 7033/2023 — Bill to regulate development and use of AI | Bill | Proposed | 2024 |
| Project 6524/2023 — Bill on digital labeling for AI systems | Bill | Proposed | 2023 |
Enforcement Bodies
| Agency | Mandate | Key Powers | Website |
|---|---|---|---|
| Presidency of the Council of Ministers (PCM) - SGTD | National technical-normative authority for AI and digital transformation. | Issue guidelines, supervise high-risk AI, coordinate national strategy. | https://www.gob.pe/pcm |
| National Data Protection Authority (ANPDP) | Oversight of personal data processing and privacy compliance. | Audit algorithms, impose fines for privacy violations, issue data guidelines. | https://www.gob.pe/minjus |
| Ministry of Foreign Affairs (MRE) | Implementation of digital transformation in consular services. | Regulate consular AI tools, ensure interoperability of overseas systems. | https://www.gob.pe/rree |
| Public Prosecutor's Office (Ministerio Público) | Investigation and prosecution of criminal offenses. | Investigate AI-facilitated crimes, apply aggravating circumstances in court. | https://www.gob.pe/mpfn |
Related Regulations
Peru - AI Regulation Implementation (115-2025)
Peru93% similar
Peru - AI Use as Aggravating Circumstance (32314/2025)
Peru92% similar
Colombia - AI Regulation Overview
Colombia91% similar
Peru - AI Promotion Law (31814)
Peru91% similar
Central and South America - AI Regulation Overview
Central and South America91% similar
More AI regulation in Peru
- Peru - Digital Government Framework (1412/2018)
- Peru - Digital Transformation Regulation (015-2025)
- Peru - Digital Transformation in Consulates (32082/2024)
- Peru - National AI Strategy
- Peru - Digital Transformation Policy (085-2023-PCM)
- Peru - AI Pedagogy in Education (10717/2024)
- Peru - Penal Code AI Modifications (10525/2024)
- Peru - AI Use in Public Entities (6927/2023)
© Regulations.AI using Gemini 3 Flash Preview · updated on 6 Jan 2026