guideline · Effective Jan 1, 2025
CL regulates AI through Directiva N° 45 — Personal Data in Public Procurement.
Directiva N° 45 — Personal Data in Public Procurement · effective 2025
Updated 60 days ago · 3 sources · confidence: medium
Overview
Chile has established itself as a pioneer in the Latin American region regarding the governance and ethical deployment of artificial intelligence. This leadership is not accidental but the result of a sustained, multi-year effort to integrate digital technologies into the national fabric while safeguarding the democratic values that define the nation. The journey began with the 2021 National Artificial Intelligence Policy, which provided a foundational vision for the country's technological future. However, the rapid acceleration of AI capabilities, particularly in the realm of generative models and large-scale data processing, necessitated a more robust and legally binding approach. Consequently, in 2024, Chile updated its National AI Policy through Decree No. 12, shifting the focus from mere promotion to a comprehensive governance model that prioritizes human rights, social equity, and environmental sustainability. This strategic update serves as a ten-year roadmap, guiding the public sector, private industry, and academic institutions toward a shared goal of 'AI for Good.' The current regulatory landscape is a sophisticated blend of horizontal laws, such as the Framework Law on Cybersecurity and the modernized Data Protection Law, and sector-specific guidelines that address the unique challenges of AI in finance, health, and consumer services. By aligning its domestic regulations with international benchmarks like the OECD AI Principles and the EU AI Act, Chile ensures that its digital economy remains competitive, interoperable, and, most importantly, trusted by its citizens. The maturity of this framework is evidenced by the creation of specialized enforcement bodies like the National Cybersecurity Agency (ANCI) and the Agency for the Protection of Personal Data, which provide the necessary oversight to transform ethical principles into enforceable legal mandates. As Chile moves toward the full implementation of its AI-specific legislation, it continues to serve as a model for how a developing nation can navigate the complexities of the fourth industrial revolution with foresight and responsibility.
Regulatory approach
The Chilean model is characterized by 'Dynamic Regulation,' a philosophy that balances the need for legal certainty with the inherent agility of technological advancement. Instead of a static law that might become obsolete, the government uses a combination of high-level statutory principles and agile administrative guidelines. The pending AI Bill (Boletín 16821-19) is the centerpiece of this strategy, adopting a risk-based architecture that mirrors the European Union's AI Act. This bill classifies AI systems into four distinct risk categories: Unacceptable Risk, High Risk, Limited Risk, and Minimal Risk. Prohibited systems include those that use subliminal techniques to distort behavior or exploit vulnerabilities of specific groups, as well as real-time remote biometric identification in public spaces for law enforcement, subject to narrow exceptions. High-risk systems, such as those used in critical infrastructure, education, employment, or essential private services, must undergo rigorous 'Conformity Assessments' and maintain detailed technical documentation. Limited-risk systems, like chatbots or deepfake generators, are subject to transparency obligations, ensuring users are aware they are interacting with an automated system. This approach ensures that innovation is not stifled in low-risk areas while providing a safety net for applications that could impact fundamental rights. Furthermore, the regulatory approach is 'Human-Centric,' meaning that human oversight is not just a recommendation but a requirement for high-risk systems. The government also utilizes 'Regulatory Sandboxes' to allow for the testing of AI innovations in the public sector under controlled conditions, fostering a culture of 'learning by doing' among regulators and developers alike. The governance of AI in Chile is a distributed but coordinated effort involving several specialized agencies. The Ministry of Science, Technology, Knowledge, and Innovation (MinCiencia) acts as the primary policy lead, responsible for updating the National AI Policy and chairing the 'Inter-ministerial Commission on AI.' This commission ensures that AI policy is integrated across various government departments, including Economy, Justice, and Education. The operational enforcement of AI-related rules falls to the newly created Agencia Nacional de Ciberseguridad (ANCI) for matters of system security and the forthcoming Agencia de Protección de Datos Personales for matters of privacy and automated processing. This separation of powers ensures that AI systems are audited both for their technical resilience and their impact on individual privacy rights. The Division of Government Digital (DGD) within the Ministry Secretariat General of the Presidency (Segpres) monitors AI adoption across public services, ensuring that the state leads by example in ethical deployment. The National Consumer Service (SERNAC) plays a critical role in the private sector, supervising AI use in commercial relationships and protecting consumers from algorithmic bias or manipulative practices. The Council for Transparency (CPLT) ensures that algorithmic systems used by the state are explainable and accessible to the public, upholding the principle of administrative transparency. This multi-agency fabric is designed to prevent regulatory gaps, with the pending AI Law expected to further formalize a 'Technical Advisory Council on AI' to provide cross-sectoral expertise on high-risk classifications and technical standards.
Enforcement & penalties
Enforcement in the Chilean AI ecosystem is characterized by a graduated sanctioning regime that scales with the severity of the infraction and the size of the entity. Under the Framework Law on Cybersecurity (Law 21.663), entities classified as Operators of Vital Importance (OIV) can face significant administrative fines for failing to report incidents or maintain security standards, with penalties reaching up to several thousand Monthly Tax Units (UTM). The new Data Protection Law (Law 21.719) introduces a robust sanctioning title administered by the new Agency, which includes corrective measures, temporary suspensions of data processing, and substantial pecuniary fines for serious breaches of data subject rights. Very grave infractions can lead to fines of up to 20,000 UTM, which is approximately 1.3 million USD, or up to 4% of the entity's annual revenue. Beyond administrative fines, Chile is actively updating its Criminal Code to address AI-enabled harms. Several legislative motions seek to establish the use of AI as an aggravating circumstance in crimes like fraud, identity usurpation, and the dissemination of non-consensual deepfakes. Enforcement also includes 'soft' measures, such as the power of the DGD to request information and audit public sector AI deployments, and the ability of SERNAC to initiate collective actions against companies using manipulative AI practices that harm consumer interests. The pending AI Bill will add another layer of enforcement, allowing the regulator to order the withdrawal of high-risk AI systems from the market if they fail to meet safety or transparency standards, ensuring that the cost of non-compliance outweighs the benefits of cutting corners.
Data protection
Chile's data protection landscape is currently in a transformative 'vacatio legis' period following the publication of Law No. 21.719 in December 2024. This law represents a comprehensive overhaul of the previous 1999 framework (Law 19.628), aligning Chilean standards with the EU's GDPR. It introduces core principles of lawful processing, including purpose limitation, proportionality, and data minimization. Crucially for AI, the law recognizes rights to portability, opposition to profiling, and the right to human intervention in automated decisions. The law is scheduled to fully enter into force on December 1, 2026, giving organizations time to implement the required technical and organizational measures. The new framework also establishes the Agencia de Protección de Datos Personales as an autonomous technical body with the power to issue binding instructions and conduct inspections. For AI developers, this means mandatory Data Protection Impact Assessments (DPIAs) for high-risk processing and the requirement to maintain a Record of Processing Activities (RAT). Furthermore, the law regulates the voluntary 'Models of Prevention of Infringements' (MPI), which allow companies to certify their compliance programs to mitigate liability. The law also places strict controls on 'Sensitive Data,' including biometric and genetic information, which are frequently used in AI systems for identification or health analysis. Until the new law is fully active, the SERNAC and the Council for Transparency continue to provide interim oversight based on existing constitutional protections and sectoral privacy rules, ensuring that the transition period does not result in a protection vacuum for Chilean citizens.
Sector-specific rules
Sector-specific AI regulation in Chile is most advanced in the public sector and consumer markets. For public administration, Oficio Circular N° 711 and the CPLT’s Resolución Exenta N° 372 set strict transparency and ethical standards. Agencies must maintain registers of automated decision systems (SDA), provide plain-language explanations of algorithmic logic, and ensure human oversight for any system affecting citizen rights. In the realm of public procurement, Directiva N° 45 from ChileCompra provides specific recommendations for handling personal data in state contracts, requiring vendors to undergo security evaluations and adhere to data minimization principles when providing AI-driven services to the government. This directive is a landmark document for ensuring data sovereignty and preventing vendor lock-in. In the private sector, the financial and consumer services industries are subject to interpretative guidance from SERNAC. This guidance focuses on the prevention of algorithmic bias in credit scoring and the prohibition of discriminatory pricing models. Additionally, the Framework Law on Cybersecurity identifies 'essential services' across sectors such as health, energy, and telecommunications, subjecting AI systems used in these domains to enhanced risk management and incident reporting duties. While healthcare-specific AI laws are still evolving, the National AI Policy identifies health as a priority area for 'sandbox' experimentation, aiming to balance clinical innovation with patient safety and data confidentiality. The Commission for the Financial Market (CMF) is also drafting guidelines for the use of AI in algorithmic trading and risk assessment, ensuring that the financial system remains stable in the face of automated volatility.
International alignment
Chile’s AI regulatory strategy is explicitly designed to harmonize with international standards, particularly those of the OECD and UNESCO. As an OECD member, Chile has integrated the OECD AI Principles—such as transparency, explainability, and accountability—into its National AI Policy and the pending AI Bill. The influence of the European Union’s AI Act is also highly visible in the risk-based architecture of Chile’s legislative proposals, which adopt similar definitions of AI systems and tiered categories of risk. This alignment is a strategic choice intended to facilitate digital trade and ensure that Chilean AI exports meet global compliance requirements. Furthermore, Chile has been a vocal participant in regional and global forums, such as the Santiago Declaration on AI in Latin America and the Caribbean, which promotes a regional approach to AI ethics. The country frequently references UNESCO’s Recommendation on the Ethics of Artificial Intelligence as a foundational text for its rights-based approach. Chile also participates in the 'Global Partnership on AI' (GPAI) and has strong bilateral agreements with the EU to facilitate data flows, provided that Chilean standards remain 'adequate' under GDPR. This international outlook extends to technical standards, with the government encouraging the adoption of ISO/IEC standards for AI risk management and quality assurance to ensure interoperability with global markets. By positioning itself as a reliable digital hub, Chile aims to attract foreign investment while ensuring that its domestic regulatory environment remains robust and respected on the world stage.
What's next
The most significant upcoming development is the expected passage and implementation of the 'Proyecto de Ley que regula los Sistemas de Inteligencia Artificial' (Boletín 16821-19). This bill will provide the definitive legal framework for AI in Chile, establishing the technical advisory bodies and the formal certification process for high-risk systems. Stakeholders are also closely watching the 2026 full entry into force of the Data Protection Law, which will trigger the active supervision of the new Data Protection Agency. This period is expected to see a flurry of secondary rulemaking, including decrees defining the technical specifications for AI impact assessments and the registration of automated systems. Additionally, Chile is exploring the frontier of 'neuro-rights,' with ongoing legislative discussions regarding the protection of mental privacy and the regulation of neurotechnology-AI interfaces. The government is also expected to launch more supervised 'regulatory sandboxes' to allow for the testing of AI innovations in the public sector under controlled conditions. As the ANCI becomes fully operational, new general instructions regarding AI-related cyber-incident reporting thresholds are anticipated. These developments signal a move toward a more granular and technically specific regulatory environment, where high-level principles are translated into enforceable technical standards and audit protocols. The government is also considering a 'National Registry of AI Systems' to track the deployment of high-risk models across the country, providing a centralized database for transparency and accountability. As the ecosystem matures, the focus will likely shift from foundational legislation to the practical challenges of algorithmic auditing and the mitigation of systemic biases in large-scale AI deployments.
guideline · Effective Jan 1, 2025
act · Effective Jan 1, 2024
act · Effective Jan 1, 2024
policy · Effective Jan 1, 2024
regulation · Effective Jan 1, 2024
guideline · Effective Jan 1, 2024
act · Effective Jan 1, 2024
guideline · Effective Jan 1, 2023
guideline · Effective Jan 1, 2022
act · Effective n/a
EU institutions
policy · Effective n/a
policy · Effective n/a
policy · Effective Jan 1, 2023
policy · Effective Jan 1, 2023
advisory
Policy leadership and AI strategy coordination
enforcement
National cybersecurity oversight
advisory
Consumer rights protection
advisory
Public transparency and data access
Mar 2, 2026 · news
UNESCO and CENIA strengthen partnership to advance ethical artificial
Open source →Aug 4, 2025 · law_amended
The Ministry of Science promotes cross-cutting dialogue for a broadly supported Artificial Intelligence Law
Open source →Jul 1, 2025 · law_amended
Tech and business sector concerns over Chile's AI bill
Open source →May 14, 2025 · news
China President Xi meets Chile President Gabriel Boric
Open source →Apr 22, 2025 · news
Brazil and Chile expand strategic partnership on AI
Open source →Feb 12, 2025 · news
Chile leads Latam-GPT project
Open source →Feb 10, 2025 · news
Paris Charter on AI signed
Open source →Oct 20, 2024 · law_amended
Latin American delegates visit AI expertise centres in Europe, kickstarting AI regulation dialogue between EU and Latin America
Open source →Aug 9, 2024 · international_agreement
Latin American countries adopt sweeping AI declaration
Open source →May 6, 2024 · law_amended
AI Bill introduced
Open source →May 3, 2024 · law_amended
Chile launches national AI policy and introduces AI bill following UNESCO´s recommendations
Open source →May 1, 2024 · law_amended
Chile to introduce new AI regulation bill in May 2024
Open source →