regulation · Effective Jan 1, 2025
PE regulates AI through Supreme Decree No. 115-2025-PCM — Regulation of Law No. 31814.
Supreme Decree No. 115-2025-PCM — Regulation of Law No. 31814 · effective 2025
Updated 60 days ago · 3 sources · confidence: medium
Overview
Peru's strategic approach to artificial intelligence is deeply rooted in its broader National Digital Transformation System (SNTD), which was established to centralize and harmonize the country's digital evolution. The journey began in earnest with the enactment of Decree-Law No. 1412, the Digital Government Law, which established the legal foundations for digital identity, interoperability, and the use of emerging technologies in public administration. This was followed by the National Policy for Digital Transformation to 2030, a landmark document that identified AI as a transformative force capable of addressing systemic inefficiencies in the Peruvian economy. Law No. 31814, passed in 2023, represents the formalization of these aspirations into a concrete regulatory framework. This law does not merely encourage AI adoption; it mandates that such adoption occur within a framework of ethical responsibility, transparency, and human-centricity. By centralizing authority within the Presidency of the Council of Ministers (PCM), Peru has ensured that AI policy is not siloed within individual ministries but is instead treated as a cross-cutting national priority. This centralized model allows for a more cohesive response to the rapid advancements in generative AI and large language models, ensuring that the state can pivot its regulatory stance as the technology evolves. The framework also emphasizes the importance of digital talent, recognizing that a robust regulatory environment must be matched by a workforce capable of developing and managing these complex systems.
Regulatory approach
The Peruvian regulatory philosophy is defined by a sophisticated risk-based classification system, formalized in Supreme Decree No. 115-2025-PCM. This system categorizes AI applications into three distinct tiers: prohibited, high-risk, and acceptable risk. Prohibited AI systems are those that pose an existential or unacceptable threat to fundamental rights, such as systems designed for subliminal manipulation that results in physical or psychological harm, or mass surveillance systems that lack a specific legal mandate and judicial oversight. High-risk systems, which include AI used in critical infrastructure management, educational assessment, recruitment, and credit scoring, are subject to a rigorous compliance regime. Developers and users of high-risk AI must conduct mandatory Algorithmic Impact Assessments (AIA), maintain detailed technical documentation, and ensure that a human remains "in the loop" to oversee automated decisions. This risk-based approach is designed to be dynamic, allowing the SGTD to update the list of high-risk applications as new use cases emerge. Acceptable risk systems, which comprise the majority of AI applications like spam filters or video game AI, are subject to minimal transparency requirements, primarily focused on informing the user that they are interacting with an AI. This nuanced approach ensures that Peru remains a competitive destination for tech investment while providing a safety net that protects its citizens from the most egregious potential abuses of algorithmic power. The Presidency of the Council of Ministers (PCM) sits at the apex of Peru's AI governance structure. Within the PCM, the Secretariat of Government and Digital Transformation (SGTD) functions as the national technical-normative authority. The SGTD's role is multifaceted: it issues technical guidelines, maintains the National Registry of High-Risk AI Systems, and coordinates the implementation of the National AI Strategy (ENIA). This centralization is critical for ensuring interoperability across the public sector, preventing a fragmented landscape where different agencies use incompatible or insecure AI tools. Supporting the SGTD is the National Data Protection Authority (ANPDP), which ensures that AI systems comply with the Law on Personal Data Protection (Law No. 29733). The ANPDP has the power to audit algorithms to detect bias or unauthorized data processing. Additionally, the National Center for Strategic Planning (CEPLAN) and the National Council for Science, Technology and Technological Innovation (CONCYTEC) provide long-term strategic guidance and support for AI research and development, ensuring that the regulatory framework remains aligned with the country's broader socio-economic goals. The interaction between these bodies creates a checks-and-balances system where innovation is promoted by the SGTD but scrutinized by the ANPDP and the judiciary.
Enforcement & penalties
Enforcement of AI regulations in Peru is divided into administrative and criminal tracks. Administratively, the SGTD has the authority to monitor compliance with the risk-based framework established by DS 115-2025-PCM. Public and private entities that fail to register high-risk systems or neglect mandatory impact assessments can face administrative sanctions, including fines and the suspension of AI operations. These sanctions are governed by the General Administrative Procedure Law (Law No. 27444), ensuring due process for all parties. On the criminal side, Law No. 32314 has introduced a significant deterrent by amending the Penal Code. When AI is used to facilitate a crime, such as creating deepfakes for extortion or using automated bots for large-scale fraud, the court is required to increase the base sentence by up to one-third. This "AI Aggravator" is one of the first of its kind globally and reflects Peru's commitment to protecting its citizens from the unique harms of synthetic media and algorithmic deception. The Public Prosecutor's Office and the National Police's specialized cybercrime units are tasked with investigating these offenses, utilizing new digital evidence standards to track the origin and deployment of malicious AI. The judiciary also plays a role in reviewing administrative appeals, ensuring that the SGTD's enforcement actions are proportionate and legally sound.
Data protection
The intersection of AI and data privacy is governed by the Law on Personal Data Protection (Law No. 29733) and its 2025 updates. The Peruvian framework is built on the principle that personal data is a fundamental right, and its processing by AI systems must be transparent, secure, and limited to a specific, legitimate purpose. The ANPDP requires that AI developers implement "privacy by design" and "privacy by default" principles. For systems that process sensitive data, such as biometric or health information, developers must conduct a Data Protection Impact Assessment (DPIA) in addition to the standard AI risk assessment. The 2025 AI Regulation further clarifies that individuals have the right to an explanation of automated decisions that significantly affect them, aligning Peru with the "right to explanation" found in the GDPR. Furthermore, the Digital Government Law (DL 1412) mandates strict security protocols for data stored in the National Data Center, ensuring that AI systems used by the state are protected against cyberattacks and data breaches. The ANPDP also issues specific guidelines for the use of AI in profiling and automated decision-making, ensuring that these practices do not lead to systemic discrimination or the erosion of individual autonomy.
Sector-specific rules
Peru has adopted a hybrid approach that combines horizontal AI laws with sector-specific mandates. The most prominent example is the consular sector, where Law No. 32082 authorizes the Ministry of Foreign Affairs to use AI for 24/7 automated citizen services. These rules specify that while AI can handle routine inquiries and document verification, any decision that impacts a citizen's legal rights must be reviewed by a human consular officer. In the education sector, the Ministry of Education (MINEDU) is developing guidelines for the ethical use of generative AI in classrooms, focusing on protecting the data of minors and ensuring that AI tools are used to enhance, rather than replace, pedagogical interaction. In the financial sector, the Superintendency of Banking, Insurance, and AFPs (SBS) is monitoring the use of AI in credit scoring and fraud detection, ensuring that algorithmic models do not result in discriminatory lending practices. In the realm of public safety, the Ministry of the Interior is exploring the use of AI for predictive policing and facial recognition, though these applications are subject to the strict "high-risk" requirements of the 2025 Regulation. These sectoral rules are designed to address the unique technical and ethical challenges of different industries while remaining anchored in the national risk-based framework overseen by the SGTD.
International alignment
Peru's AI strategy is explicitly designed to align with international standards, particularly those of the OECD and the European Union. As a candidate for OECD accession, Peru has integrated the OECD Recommendation on Artificial Intelligence into its national principles, emphasizing transparency, accountability, and the promotion of digital talent. The risk-based classification system in DS 115-2025-PCM is heavily influenced by the EU AI Act, providing a familiar regulatory environment for international technology companies. Peru is also an active participant in UNESCO's Recommendation on the Ethics of Artificial Intelligence, focusing on the social and cultural impacts of technology. Regionally, Peru plays a leading role in the eLAC (Digital Agenda for Latin America and the Caribbean) and the Andean Community (CAN), advocating for harmonized AI standards that facilitate cross-border data flows and collaborative innovation. This internationalist outlook is intended to position Peru as a regional hub for ethical AI development, attracting foreign investment while ensuring that domestic regulations are robust enough to withstand global technological shifts. Peru also participates in the Global Partnership on AI (GPAI), contributing to international research on AI safety and governance.
What's next
The next two years will be a period of intense technical implementation for Peru's AI framework. A primary focus will be the operationalization of "Regulatory Sandboxes," as envisioned in the National AI Strategy. These sandboxes will allow startups and researchers to test high-risk AI applications in a controlled environment under the supervision of the SGTD and ANPDP, fostering innovation while mitigating potential harms. In the legislative sphere, Project 10717/2024 is expected to formalize the integration of AI pedagogy into the national school curriculum, while Project 6524/2023 aims to introduce mandatory "Digital Labeling" for all AI-generated content. This labeling requirement would serve as a critical tool in the fight against disinformation and deepfakes. Additionally, the SGTD is expected to issue a series of Technical Standards (NTP) based on ISO/IEC 42001, providing a clear certification path for companies that want to demonstrate their commitment to AI management excellence. The government is also planning to launch a National AI Observatory to monitor the socio-economic impact of AI and provide real-time data for policy adjustments. These developments signal that Peru is moving beyond the creation of primary laws toward a mature ecosystem of technical standards, specialized oversight, and proactive innovation support.
regulation · Effective Jan 1, 2025
act · Effective Jan 1, 2025
regulation · Effective Jan 1, 2025
act · Effective Jan 1, 2024
policy · Effective Jan 1, 2024
act · Effective Jan 1, 2023
policy · Effective Jan 1, 2023
policy · Effective Jan 1, 2023
act · Effective Jan 1, 2018
act · Effective n/a
Sources:
act · Effective n/a
policy · Effective Jan 1, 2020
strategy · Effective Jan 1, 2021
policy · Effective Jan 1, 2023
enforcement
National technical-normative authority for AI and digital transformation.
data_protection
Oversight of personal data processing and privacy compliance.
central_coordinator
Implementation of digital transformation in consular services.
enforcement
Investigation and prosecution of criminal offenses.
Aug 3, 2025 · news
2025 APEC Digital and AI Ministerial Statement
Open source →Nov 24, 2024 · law_amended
New updated draft of Law No. 31814 released
Open source →Aug 9, 2024 · international_agreement
Latin American countries adopt sweeping AI declaration
Open source →May 1, 2024 · law_amended
Peru launches consultation into AI regulation (Law 31814)
Open source →Feb 14, 2024 · law_amended
Peru advances with EU-inspired AI regulation
Open source →No tracked international memberships yet
Last checked May 26, 2026