policy · Effective Jan 1, 3975
Sources:
CO regulates AI through National AI Policy (CONPES 3975).
National AI Policy (CONPES 3975) · effective 3975-01
Updated 60 days ago · 2 sources · confidence: medium
Overview
Colombia’s approach to artificial intelligence (AI) regulation is characterized by a rapid transition from high-level strategic planning to a structured, risk-based legislative framework. The foundational pillar of this ecosystem is the Política Nacional de Inteligencia Artificial (CONPES 4144), adopted in February 2025, which sets a multi-year roadmap through 2030. This policy integrates AI into the broader national development goals, emphasizing inclusive economic growth, the closing of digital divides, and the protection of fundamental rights. Historically, Colombia was one of the first countries in Latin America to release an Ethical Framework for AI (2020), and it has consistently aligned its digital agenda with international standards, particularly those of the OECD and UNESCO. The current regulatory philosophy is 'human-centric,' focusing on the socio-technical implications of algorithms rather than just technical performance. Under the administration's National Digital Strategy 2023-2026, AI is treated as a transversal tool for the 'Digital Transformation of the State.' This involves not only the adoption of AI in public services but also the creation of a 'governance architecture' that coordinates the Ministry of Information and Communications Technologies (MinTIC), the Ministry of Science, Technology and Innovation (MinCiencias), and the National Planning Department (DNP). While several comprehensive bills have been archived in recent years, the active legislative docket reflects a persistent push to codify AI ethics into statutory law, ensuring that AI development remains sustainable, ethical, and responsible.
Regulatory approach
Colombia utilizes a hybrid regulatory approach that combines horizontal strategic policies with emerging sector-specific mandates. The CONPES 4144 serves as the horizontal policy guide, establishing a risk-based classification system that mirrors the European Union’s AI Act. This system categorizes AI applications into four tiers: unacceptable risk (prohibited), high risk (subject to strict audits and registration), limited risk (subject to transparency duties), and low risk. This risk-based model is intended to provide legal certainty for developers while ensuring that 'high-risk' systems—such as those used in justice, healthcare, and biometric identification—undergo rigorous impact assessments before deployment. In addition to this horizontal strategy, Colombia is increasingly adopting a 'soft law' to 'hard law' pipeline. Initial guidance often comes in the form of 'Hojas de Ruta' (Roadmaps) issued by MinCiencias or MinTIC, which are then translated into legislative proposals. For example, the Hoja de Ruta para la adopción ética y sostenible de la IA (2024) laid the groundwork for current bills regarding AI in labor and public administration. This approach allows for flexibility in a fast-evolving technological landscape while building the institutional capacity necessary for future enforcement. The regulatory stance is also 'co-regulatory,' encouraging public-private partnerships and the use of regulatory sandboxes to test AI applications in controlled environments before full-scale market entry. The governance of AI in Colombia is decentralized but coordinated through a 'whole-of-government' approach. The Departamento Nacional de Planeación (DNP) acts as the strategic steward, monitoring the implementation of CONPES policies and ensuring alignment with the National Development Plan. Operational leadership is shared between MinTIC, which focuses on digital infrastructure and technical standards, and MinCiencias, which leads on the ethical roadmap, research funding, and the development of the national AI talent pool. These entities are tasked with creating the 'National AI Observatory' to track algorithmic impacts across society. Enforcement and market surveillance fall primarily under the Superintendencia de Industria y Comercio (SIC). As the national data protection authority, the SIC has the power to investigate AI systems that process personal data and can issue corrective orders or fines. Furthermore, the Agencia Nacional Digital (AND) supports the technical implementation of AI within public administration. For sector-specific oversight, bodies like the Agencia Nacional de Seguridad Vial (ANSV) are increasingly involved in regulating AI applications within their respective domains, such as autonomous traffic management and predictive road safety analytics.
Enforcement & penalties
Currently, penalties for AI-related infractions are derived from existing administrative and data protection regimes. Under Law 1581 of 2012, the Superintendencia de Industria y Comercio (SIC) can impose administrative fines of up to 2,000 monthly minimum wages for violations related to the unauthorized processing of personal data or failure to implement security measures. The SIC also has the authority to order the temporary or permanent closure of operations involving data processing that does not comply with legal standards. In the context of AI, this extends to cases where algorithmic bias or lack of transparency leads to the infringement of privacy rights. Proposed legislation, such as Statutory Bill 154 of 2024 and Bill 442/25, seeks to introduce a more specific sanctioning regime for AI. These proposals include penalties for deploying 'unacceptable risk' systems (such as mass biometric surveillance) and fines for failing to register 'high-risk' systems in the national registry. Sanctions would include the suspension of the AI system's operation, mandatory public disclosure of the infraction, and corrective orders to retrain models that exhibit discriminatory biases. Appeals against these administrative sanctions are typically handled through the contentious-administrative jurisdiction (Jurisdicción de lo Contencioso Administrativo), following the standard procedures of the Colombian Code of Administrative Procedure (CPACA).
Data protection
The Colombian data protection framework is anchored in Ley 1581 de 2012 and Decreto 1377 de 2013, which are heavily influenced by the 'Habeas Data' constitutional principle. This framework requires explicit, informed, and prior consent for data processing, which poses significant compliance requirements for AI developers using large-scale datasets. The SIC has issued specific guidance, such as the 'Handbook on Accountability,' which encourages AI operators to adopt 'privacy by design' and 'privacy by default' principles. There are currently no strict data localization requirements, but cross-border transfers are only permitted to countries that provide 'adequate levels' of protection, as determined by the SIC. Emerging AI regulations seek to modernize this framework. Statutory Bill 154 of 2024 proposes specific amendments to Law 1581 to address 'automated decision-making.' These amendments would grant citizens the right to request an explanation of the logic behind an automated decision and the right to human intervention. Furthermore, the bill mandates Data Protection Impact Assessments (DPIAs) specifically for AI systems that process sensitive data or involve profiling. This ensures that the 'right to be forgotten' and the right to rectification are enforceable even within complex, black-box algorithmic environments.
Sector-specific rules
Sector-specific AI regulation in Colombia is most advanced in the public sector and transportation. Proyecto de Ley 417 of 2025 specifically targets the management of Petitions, Complaints, and Claims (PQRSD) in public entities. It prohibits the replacement of human judgment in 'sensitive' administrative decisions and requires that all AI-generated responses be reviewable and validatable by a public official. This ensures that the constitutional right to petition is not compromised by automated errors. In the transportation sector, Proyecto de Ley 255 of 2024 establishes guidelines for AI in road safety, focusing on predictive analytics for accident reduction while requiring strict data governance for sensor and mobility data. In the labor sector, there has been significant debate surrounding Proyecto 130 of 2023, which aimed to harmonize AI with workers' rights. Although the bill was archived, its principles—such as the mandatory disclosure of AI use in hiring and the requirement for 'human-in-the-loop' for termination decisions—continue to influence the Ministry of Labor's guidance. Additionally, the financial sector, overseen by the Superintendencia Financiera de Colombia (SFC), has seen the implementation of regulatory sandboxes (La Arenera) where fintech companies can test AI-driven credit scoring and robo-advisory services under close supervisory monitoring to prevent systemic risk and consumer harm.
International alignment
Colombia’s AI strategy is deeply rooted in international cooperation and alignment with global standards. The country is a signatory to the OECD Recommendation on Artificial Intelligence and has actively participated in the UNESCO Readiness Assessment Methodology (RAM) to evaluate its institutional capacity. CONPES 4144 explicitly references the need for 'international interoperability,' ensuring that Colombian AI standards do not create barriers to trade with major partners like the United States and the European Union. The influence of the EU AI Act is particularly evident in the risk-based classification and the emphasis on 'conformity assessments' for high-risk systems found in recent legislative drafts. Furthermore, Colombia has engaged in bilateral and multilateral agreements to foster AI development. It is a key member of the CAF (Development Bank of Latin America) AI initiatives and has collaborated with the Inter-American Development Bank (IDB) on the 'fAIr LAC' initiative to promote ethical AI in the region. These partnerships focus on technical assistance, the development of ethical toolkits for startups, and the promotion of 'Open Science.' By aligning with these international frameworks, Colombia aims to position itself as a regional leader in 'Trustworthy AI,' attracting foreign investment while maintaining high standards of human rights protection.
What's next
The future of AI regulation in Colombia will be defined by the fate of Statutory Bill 154 of 2024. If passed, this would represent the first comprehensive, binding AI law in the country, moving beyond the 'soft law' of CONPES policies. The bill is expected to undergo further debates in the 2025-2026 legislative sessions, with potential refinements to the definitions of 'high-risk' and the specific powers of the proposed National AI Observatory. Stakeholders are also anticipating the issuance of technical 'lineamientos' (guidelines) from MinTIC regarding algorithmic transparency and the standardization of 'Model Cards' for public sector AI procurement. Another significant development is the planned operationalization of the CONPES 4144 action plan. This includes the creation of a national data infrastructure and the launch of massive training programs to upskill 1 million Colombians in digital and AI competencies by 2026. As the government moves toward the 'Digital Transformation of the State,' we can expect more sector-specific decrees, particularly in healthcare (for AI diagnostics) and agriculture (for precision farming). The ongoing 'Regional Dialogues' will also play a crucial role in ensuring that future AI regulations address the specific needs of Colombia’s diverse territories and avoid exacerbating regional inequalities.
policy · Effective Jan 1, 3975
Sources:
policy · Effective Jan 1, 2025
policy · Effective Jan 1, 2025
policy · Effective Jan 1, 2025
policy · Effective Jan 1, 2024
policy · Effective Jan 1, 2024
policy · Effective Jan 1, 2024
policy · Effective Jan 1, 2024
policy · Effective Jan 1, 2024
policy · Effective Jan 1, 2023
policy · Effective Jan 1, 2023
policy · Effective Jan 1, 2023
policy · Effective Jan 1, 2021
act · Effective Jan 1, 1581
advisory
Lead agency for ICT policy and digital standards.
advisory
Coordinates AI research, development, and ethical roadmaps.
data_protection
National authority for data protection and consumer rights.
advisory
Strategic planning and monitoring of national policies (CONPES).
No tracked timeline events yet
Last checked May 26, 2026
No tracked international memberships yet
Last checked May 26, 2026