regulation · Effective Jan 1, 2024
UY regulates AI through Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (CETS No. 225).
Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (CETS No. 225) · effective 2024
Updated 60 days ago · 2 sources · confidence: medium
Overview
Uruguay has positioned itself as a pioneering force in the Latin American digital landscape, adopting a proactive and structured approach to the regulation and governance of Artificial Intelligence (AI). The country’s regulatory philosophy is characterized by a transition from early ethical guidelines to a more robust, legally mandated strategic framework. This evolution is spearheaded by the Agency for Electronic Government and Information Society (AGESIC), which operates under the Executive Branch. Uruguay’s approach is fundamentally human-centric, prioritizing the protection of fundamental rights, democratic governance, and social equity. By integrating AI policy into its broader digital agenda, the Oriental Republic aims to leverage these technologies for sustainable development while mitigating risks associated with transparency, bias, and data privacy. The maturity of Uruguay's AI ecosystem is evidenced by its recent legislative milestones and international commitments. In late 2023, the enactment of Law No. 20.212 provided a formal mandate for the creation of a national strategy, signaling a move toward more formalized governance. This was followed by the landmark signing of the Council of Europe Framework Convention on Artificial Intelligence and Human Rights in September 2025, making Uruguay the first country in Latin America to join this legally binding international instrument. The current environment is one of active implementation, where the government seeks to balance the promotion of innovation with a rigorous ethical framework, ensuring that AI deployment in both the public and private sectors aligns with the nation's long-standing tradition of rule of law and institutional stability. This institutional stability is further supported by Uruguay's high ranking in global e-government and digital participation indices, providing a fertile ground for the deployment of advanced algorithmic systems within a framework of public trust and administrative transparency.
Regulatory approach
Uruguay’s regulatory approach is currently characterized as a hybrid model that combines horizontal strategic planning with risk-based principles. Rather than a single, prescriptive 'AI Law' similar to the EU AI Act, Uruguay utilizes a framework of 'soft law' instruments—such as the National AI Strategy 2024-2030—backed by 'hard law' mandates like Article 74 of Law No. 20.212. This approach allows for flexibility in a rapidly evolving technological field while providing a clear legal basis for government action. The strategy is built upon ten guiding principles, including accountability, transparency, and non-discrimination, which serve as the evaluative criteria for AI systems across all sectors. This horizontal foundation ensures that regardless of the specific application, AI systems must respect human dignity and democratic values. The strategy emphasizes that AI is not an end in itself but a tool to improve the quality of life for citizens and the efficiency of public services. Furthermore, the Uruguayan model is increasingly adopting a risk-based and lifecycle-oriented methodology. This is particularly evident in the National AI Strategy and the commitments made under the Council of Europe treaty, which require iterative impact assessments from the design phase through to decommissioning. For the public sector, the approach is more prescriptive, with AGESIC providing specific guidelines for the ethical use of AI in government services. For the private sector, the government utilizes a collaborative governance model, encouraging adherence to international standards and ethical guidelines through multi-stakeholder dialogues and the Strategic Committee for the Public Sector on AI and Data. This dual-track approach ensures that while the state leads by example in its own digital transformation, it also fosters a safe environment for private innovation through clear expectations and international alignment. The regulatory philosophy also incorporates the concept of 'algorithmic accountability,' requiring that entities using AI be able to explain the logic behind automated decisions, especially when those decisions significantly impact individual rights or access to essential services. The primary architect of AI policy in Uruguay is the Agency for Electronic Government and Information Society (AGESIC). AGESIC’s mandate is broad, encompassing the design, development, and coordination of the National AI Strategy. It functions as the central hub for digital transformation, providing technical expertise to other government branches and leading the Strategic Committee for the Public Sector on AI and Data. AGESIC is responsible for creating the guidelines, standards, and best practices that govern the lifecycle of AI systems. Its power is derived from its ability to set mandatory standards for the public sector and its role as the primary advisor to the Executive Branch on all matters related to the information society. AGESIC also plays a crucial role in international representation, ensuring that Uruguay's AI policies remain aligned with global standards. Complementing AGESIC is the Personal Data Regulatory and Control Unit (URCDP). As the autonomous regulator for data protection, the URCDP’s mandate is critical in the context of AI, as most AI systems rely on the processing of personal data. Under Law No. 20.212, AGESIC must coordinate directly with the URCDP for any AI strategy components involving personal data. The URCDP has the power to investigate complaints, conduct audits, and impose sanctions on entities that violate data protection principles during the development or operation of AI models. This body ensures that the 'right to privacy' is not compromised by the rapid adoption of algorithmic technologies. Additionally, the Strategic Committee of the Public Sector for AI and Data serves as a high-level coordination body, bringing together various ministries and agencies to ensure a unified approach to AI governance. This committee is responsible for approving major policy initiatives and monitoring the progress of the National AI Strategy. Together, these three bodies form a robust governance structure where AGESIC focuses on strategic deployment, the URCDP ensures data compliance, and the Strategic Committee provides high-level political and inter-agency alignment.
Enforcement & penalties
Enforcement in the Uruguayan AI landscape currently operates through a combination of administrative sanctions and sector-specific penalties. For violations involving the misuse of personal data within AI systems, the URCDP has the authority to impose a range of sanctions under Law No. 18.331. These include formal warnings, reprimands, and significant financial fines. In severe cases, the URCDP can order the suspension or deletion of databases, which effectively halts the operation of an AI system that relies on illicitly processed data. The enforcement process includes a right to a hearing and an appeals process through the administrative court system, ensuring that due process is respected for both public and private entities. The URCDP's ability to conduct proactive audits is a key deterrent against the non-compliant use of AI in data-intensive sectors. In the public sector, enforcement is largely driven by administrative compliance and budgetary oversight. Since AGESIC sets the standards for government procurement and use of AI, non-compliance can lead to the rejection of projects or disciplinary actions against public officials. While Uruguay has not yet implemented a specific 'AI Penal Code,' the National AI Strategy 2024-2030 and the Council of Europe treaty signal a move toward more rigorous oversight mechanisms. This includes the establishment of an AI Observatory and the potential for new remedial mechanisms that allow citizens to challenge AI-driven decisions. As the legal framework matures, it is expected that more specific civil and potentially criminal liabilities related to AI-induced harm will be integrated into the existing legal code. The government is also exploring the use of 'regulatory sandboxes' which, while primarily aimed at innovation, also serve as a controlled environment for testing compliance and identifying potential regulatory gaps before full-scale deployment. This proactive enforcement philosophy aims to prevent harm rather than merely punishing it after the fact, aligning with the precautionary principle often cited in Uruguayan administrative law.
Data protection
Uruguay possesses one of the most robust data protection frameworks in the Americas, often cited for its alignment with European standards. Law No. 18.331 (2008) is the cornerstone of this framework, establishing that the protection of personal data is a fundamental right. Uruguay was the first non-European country to be recognized by the European Commission as providing an 'adequate' level of data protection, a status that facilitates the free flow of data between Uruguay and the EU. This adequacy is vital for the AI sector, as it allows Uruguayan companies to process European data for AI training and development without additional complex legal safeguards. The framework is built on principles of legality, purpose limitation, data minimization, and security, all of which are directly applicable to the development and deployment of AI models. For AI developers, this means that the collection of data for training models must be transparent, and data subjects must be informed of the logic involved in automated decision-making processes. Recent updates to the framework have emphasized the concept of 'Privacy by Design' and 'Privacy by Default,' which are now being integrated into AI development guidelines. The URCDP actively monitors the use of emerging technologies, ensuring that the deployment of facial recognition, predictive analytics, and generative AI remains within the bounds of the law, particularly regarding the processing of sensitive data. Furthermore, the framework includes the 'Habeas Data' action, a constitutional remedy that allows individuals to access, correct, or delete their personal data held by third parties. In the context of AI, this right is being interpreted to include the right to understand how an algorithm reached a specific conclusion about an individual. The URCDP has also issued specific guidance on the use of biometric data and the requirements for impact assessments when using high-risk automated processing. This strong data protection foundation provides the necessary legal certainty for both citizens and businesses, ensuring that AI innovation does not come at the expense of individual privacy or digital sovereignty.
Sector-specific rules
While Uruguay’s primary AI strategy is horizontal, certain sectors have begun to develop specific guidelines to address unique risks. In the financial sector, the Central Bank of Uruguay (BCU) monitors the use of algorithms in credit scoring and automated trading to ensure market stability and consumer protection. Although there is no specific 'AI in Finance' law, the BCU utilizes its existing regulatory powers to oversee the transparency and fairness of financial algorithms, requiring banks to maintain human oversight of automated systems. Similarly, in the healthcare sector, the Ministry of Public Health (MSP) is increasingly involved in the governance of digital health tools, ensuring that AI-driven diagnostic systems meet strict clinical validation and data security standards. The MSP's 'Salud.uy' program integrates AI into the national electronic health record system, necessitating specific protocols for data anonymization and ethical use. The public administration is perhaps the most regulated sector regarding AI use. AGESIC has issued specific guidelines for the use of AI in government, which include requirements for transparency in algorithmic decision-making and the prevention of bias in social service delivery. These guidelines are mandatory for all central administration bodies and serve as a model for local governments. In the realm of labor and employment, the National AI Strategy highlights the need to protect workers' rights in the face of automation. While specific legislation for autonomous vehicles or AI in the judiciary is still in the early stages of discussion, the government’s approach is to apply existing sectoral regulations—such as transport safety laws and judicial procedural codes—to AI applications until more specialized rules are enacted. This sectoral approach ensures that the unique risks of different AI applications are addressed by the relevant experts, while still adhering to the overarching national principles of transparency and human rights protection.
International alignment
Uruguay’s AI policy is deeply rooted in international cooperation and alignment with global standards. The country is a member of the D9 (formerly D7) group of digitally advanced nations, where it shares best practices on digital government and AI ethics. Uruguay has explicitly aligned its National AI Strategy with the OECD Principles on Artificial Intelligence and the UNESCO Recommendation on the Ethics of Artificial Intelligence. This alignment ensures that Uruguay’s domestic policies are interoperable with those of its major trading partners and reflect a global consensus on responsible AI development. The country's participation in the Global Partnership on Artificial Intelligence (GPAI) further underscores its commitment to collaborative governance. The most significant recent development in international alignment is Uruguay’s signature of the Council of Europe Framework Convention on AI (CETS No. 225) in 2025. By becoming the first Latin American signatory, Uruguay has committed to a high standard of legal protection for human rights in the AI era. This move not only strengthens its ties with European regulatory models—such as the EU AI Act—but also positions Uruguay as a bridge between Latin American regional interests and global governance frameworks. The Montevideo Declaration on AI, adopted in 2024, further reinforces this by establishing a regional roadmap for ethical AI, emphasizing digital sovereignty and regional cooperation among Latin American and Caribbean nations. This declaration calls for the creation of a regional AI observatory and the harmonization of data protection standards across the continent. Uruguay's leadership in these international fora reflects its belief that AI governance must be a collective effort, balancing the needs of small, innovative economies with the global requirement for ethical and safe technological development. This internationalist approach also facilitates the attraction of foreign investment, as companies can be confident that Uruguay's regulatory environment is consistent with global best practices.
What's next
The future of AI regulation in Uruguay is expected to focus on the formal ratification and implementation of the Council of Europe Framework Convention. This will likely require the introduction of new legislative measures to establish the specific oversight and remedial mechanisms mandated by the treaty. The government is also expected to further develop the 'AI Observatory' within AGESIC, which will serve as a permanent body for monitoring the societal impact of AI and providing evidence-based recommendations for future policy adjustments. Public consultations are ongoing regarding the specific implementation of the 12 lines of action outlined in the 2024-2030 Strategy, with a particular focus on building national AI capabilities and fostering a 'sovereign' data ecosystem. Another key area of development is the potential for sectoral regulations in high-risk areas such as facial recognition in public spaces and AI in the criminal justice system. As the National AI Strategy moves from the planning to the implementation phase, there will be an increased focus on building national capabilities, including the development of a 'sovereign AI' infrastructure and specialized training programs for the workforce. Legislators are also monitoring international trends, particularly the enforcement of the EU AI Act, to determine if more prescriptive requirements for 'high-risk' AI systems should be adopted into Uruguayan law to maintain its 'adequacy' status and ensure a competitive, safe digital economy. The government is also exploring the creation of an 'AI Ethics Committee' with the power to review high-impact public sector projects before they are deployed. This proactive approach aims to ensure that Uruguay remains at the forefront of ethical AI innovation, providing a stable and predictable environment for both citizens and the technology sector. The integration of AI into the national education system and the promotion of 'AI for Good' initiatives are also expected to be major themes in the coming years, as the country seeks to leverage these technologies for social inclusion and environmental sustainability.
regulation · Effective Jan 1, 2024
policy · Effective Jan 1, 2024
central_coordinator
Leads the digital transformation of the state and coordinates the National AI Strategy.
data_protection
Autonomous body responsible for ensuring compliance with personal data protection laws.
central_coordinator
Apex governance body for coordinating AI policy across the public sector.
Sep 1, 2025 · news
Uruguay signs Council of Europe’s global AI treaty
Open source →Oct 20, 2024 · law_amended
Latin American delegates visit AI expertise centres in Europe, kickstarting AI regulation dialogue between EU and Latin America
Open source →Oct 2, 2024 · international_agreement
Montevideo Declaration adopted
Open source →Aug 9, 2024 · international_agreement
Latin American countries adopt sweeping AI declaration
Open source →Jul 5, 2024 · law_amended
No tracked international memberships yet
Last checked May 26, 2026
policy · Effective Jan 1, 2024
act · Effective Jan 1, 2023
Uruguay releases recommendations on AI regulation