policy · Effective Jan 1, 2024
CR regulates AI through National Artificial Intelligence Strategy (ENIA) 2024-2027.
National Artificial Intelligence Strategy (ENIA) 2024-2027 · effective 2024
Updated 60 days ago · 2 sources · confidence: medium
Overview
As of early 2026, Costa Rica has solidified its position as a pioneer in the Latin American digital landscape by becoming the first Central American nation to implement a comprehensive National Artificial Intelligence Strategy (Estrategia Nacional de Inteligencia Artificial - ENIA) for the period 2024-2027. The country's regulatory philosophy is deeply rooted in its long-standing tradition of protecting human rights, democratic values, and environmental sustainability. This approach is not merely reactive but proactive, aiming to leverage AI as a catalyst for socio-economic development while establishing robust guardrails against algorithmic bias, misinformation, and privacy infringements. The government, led by the Ministry of Science, Innovation, Technology and Telecommunications (MICITT), views AI as an essential component of the national digital transformation agenda, emphasizing that technological progress must remain at the service of human dignity. The maturity of Costa Rica's AI ecosystem is reflected in its active participation in international forums and its early adoption of global standards. Since joining the OECD in 2021, Costa Rica has consistently aligned its domestic policies with the OECD Principles on Artificial Intelligence. Furthermore, the country was an early adopter of the UNESCO Recommendation on the Ethics of Artificial Intelligence, which served as a foundational document for its national strategy. This international alignment has fostered a regulatory environment that prioritizes transparency, accountability, and inclusive growth. By 2026, the focus has shifted from high-level strategic planning to the institutionalization of these principles through legislative action and the creation of specialized oversight bodies, ensuring that both public and private sector AI deployments are subject to rigorous ethical and technical standards.
Regulatory approach
Costa Rica employs a hybrid regulatory approach that combines horizontal policy frameworks with emerging sector-specific guidelines. Currently, the primary regulatory instrument is the National AI Strategy (ENIA), which functions as a high-level policy guide for the entire public administration and provides a roadmap for private sector adoption. However, the country is rapidly moving toward a more prescriptive, risk-based legislative model. This shift is exemplified by the introduction and debate of Bill No. 23.771 (Law for the Regulation of Artificial Intelligence), which draws significant inspiration from the European Union's AI Act. This proposed legislation seeks to categorize AI systems based on the level of risk they pose to fundamental rights—ranging from 'unacceptable risk' systems that are prohibited, to 'high-risk' systems subject to strict transparency and safety requirements. While the legislative framework is still evolving, the current regulatory environment relies heavily on 'soft law' mechanisms, such as ethical guidelines and technical standards issued by MICITT. These guidelines emphasize 'human-in-the-loop' requirements, ensuring that automated decisions are subject to human oversight. At the same time, existing laws, particularly the Law on the Protection of the Person against the Processing of their Personal Data (Law 8968), provide a binding legal foundation for AI applications involving personal information. This dual-track approach allows the government to foster innovation through flexible policy while maintaining a baseline of legal protection through established privacy and consumer protection statutes. The ultimate goal is a balanced ecosystem where innovation is encouraged within a clear, predictable, and ethically grounded legal framework. The primary authority for AI policy and governance in Costa Rica is the Ministry of Science, Innovation, Technology and Telecommunications (MICITT). MICITT is responsible for the design, implementation, and monitoring of the National AI Strategy. It acts as the central coordinator between the public sector, private industry, and academia. Within MICITT, the Digital Governance Directorate plays a crucial role in setting technical standards and promoting the ethical use of AI in public administration. MICITT also leads the National Laboratory for Artificial Intelligence (LANIA), which serves as a hub for research, development, and the testing of AI solutions in a controlled environment, ensuring they meet safety and performance benchmarks before widespread deployment. Complementing MICITT's policy role is the Agency for the Protection of Individuals' Data (PRODHAB), which serves as the enforcement body for privacy and data protection. As AI systems are increasingly data-intensive, PRODHAB's mandate has expanded to include the oversight of how AI algorithms process personal information. PRODHAB has the power to investigate complaints, conduct audits of databases, and impose sanctions on entities that violate data privacy rights. Additionally, the proposed AI legislation (Bill 23.771) envisions the creation of an Inter-institutional Commission for Artificial Intelligence, which would serve as a specialized regulatory body with the power to certify high-risk AI systems and ensure compliance with the new risk-based standards. The Ministry of Economy, Industry and Commerce (MEIC) also plays a supporting role by monitoring the market for consumer protection issues related to AI-powered products.
Enforcement & penalties
Enforcement of AI-related regulations currently operates through the established mechanisms of the Data Protection Law (Law 8968). PRODHAB is empowered to impose administrative sanctions for violations related to the unauthorized processing of personal data, lack of informed consent, or failure to secure personal information. Fines are generally calculated based on 'base salaries' (salarios base), with penalties ranging from five to thirty base salaries depending on the severity of the infraction. In cases of serious breaches, PRODHAB can order the immediate suspension of data processing activities or the deletion of illegally obtained databases, which can effectively shut down non-compliant AI systems. Under the proposed Law for the Regulation of Artificial Intelligence (Bill 23.771), the enforcement regime is expected to become significantly more stringent. The bill proposes a tiered penalty structure modeled after international standards, where fines could be calculated as a percentage of a company's total annual turnover. For the most serious violations, such as deploying prohibited AI systems that manipulate human behavior or exploit vulnerabilities, the proposed fines could reach several million dollars. Furthermore, the bill emphasizes the right of individuals to seek judicial recourse and compensation for damages caused by AI systems. Appeals against administrative decisions made by MICITT or PRODHAB are handled through the Contentious-Administrative and Civil Treasury Jurisdiction (Jurisdicción Contencioso-Administrativa y Civil de Hacienda), ensuring a judicial check on regulatory actions.
Data protection
Costa Rica's data protection framework is anchored by Law No. 8968, enacted in 2011, which establishes the fundamental right to 'informational self-determination.' This law applies to all automated and manual databases, both in the public and private sectors. Key principles include informed consent, purpose limitation, and data quality. For AI developers, this means that any personal data used for training or operating AI systems must be collected with the explicit, documented consent of the data subject, and the data must only be used for the specific purposes disclosed at the time of collection. Sensitive data, such as health information or political opinions, receives higher protection and requires even more rigorous consent protocols. As of 2026, the framework is undergoing a significant modernization through Bill No. 23.097, which seeks to align national law with the EU General Data Protection Regulation (GDPR). This reform introduces new concepts critical for AI, such as 'privacy by design' and 'privacy by default,' as well as mandatory Data Protection Impact Assessments (DPIAs) for high-risk processing activities. It also expands data subject rights to include the right to data portability and the right to object to fully automated decision-making. These changes are designed to ensure that Costa Rica remains a 'safe harbor' for international data transfers and a competitive destination for AI-driven businesses that prioritize ethical data handling and respect for individual privacy rights.
Sector-specific rules
In the financial sector, the General Superintendency of Financial Entities (SUGEF) and the Central Bank of Costa Rica have begun issuing guidelines regarding the use of AI in credit scoring, fraud detection, and automated trading. These rules emphasize the need for 'explainability' in financial algorithms to prevent discriminatory practices and ensure that consumers can understand the basis for decisions that affect their financial standing. Financial institutions are required to maintain robust internal governance frameworks that include regular audits of AI models to detect and mitigate algorithmic bias, particularly in lending decisions. The healthcare sector, overseen by the Ministry of Health and the Costa Rican Social Security Fund (CCSS), has also seen the introduction of specific protocols for AI-assisted diagnostics and the management of electronic health records (EDUS). These protocols prioritize patient safety and data confidentiality, requiring that AI tools used in clinical settings undergo rigorous validation and are used only as decision-support systems for medical professionals, rather than autonomous diagnostic tools. Furthermore, the National Health Research Council (CONIS) provides oversight for clinical trials involving AI, ensuring that ethical standards are maintained in medical research involving human subjects and their biological data. These sector-specific interventions ensure that the unique risks associated with AI in critical areas of human life are addressed with precision and care.
International alignment
Costa Rica’s AI regulatory strategy is characterized by a high degree of international alignment, particularly with the OECD and UNESCO. As an OECD member, Costa Rica has integrated the 2019 OECD AI Principles into its National Strategy, focusing on inclusive growth, human-centric values, transparency, and accountability. The country also actively participates in the Global Partnership on Artificial Intelligence (GPAI), contributing to international efforts to develop shared standards for responsible AI. This commitment to global norms is intended to facilitate cross-border collaboration and ensure that Costa Rican AI companies can compete in international markets by adhering to recognized ethical benchmarks. The influence of the European Union’s AI Act is also highly visible in Costa Rica's legislative debates. Lawmakers have explicitly stated that Bill 23.771 is intended to harmonize Costa Rica's domestic rules with the EU's risk-based approach, which is increasingly seen as the global gold standard for AI regulation. By adopting similar definitions and risk categories, Costa Rica aims to reduce regulatory friction for European companies operating in the country and vice versa. Additionally, Costa Rica has signed bilateral agreements with several nations to cooperate on AI research and cybersecurity, further embedding its national framework within a global network of digital governance and ensuring that its policies remain at the forefront of international best practices.
What's next
The most significant anticipated development in 2026 is the final passage and implementation of the Law for the Regulation of Artificial Intelligence (Bill 23.771). Once enacted, this law will trigger a transition period during which companies and government agencies must conduct risk assessments of their existing AI systems and register high-risk applications with the new regulatory authority. The establishment of the Inter-institutional Commission for AI will also be a major milestone, providing a dedicated technical body to oversee the complex challenges of algorithmic auditing and certification. This will likely lead to the publication of more detailed technical regulations and standards for specific high-risk domains, such as biometric identification and critical infrastructure management. Another key area of focus is the continued expansion of the National AI Strategy's 'Action Plan,' which includes the rollout of 5G infrastructure and the creation of regional 'Innovation Hubs' outside the Greater Metropolitan Area (GAM). These efforts are aimed at democratizing access to AI technologies and ensuring that the benefits of the digital economy are distributed across the entire country. Furthermore, the government is expected to launch new initiatives focused on 'AI for Climate Action,' leveraging machine learning to support Costa Rica's ambitious decarbonization goals. As the regulatory framework matures, the emphasis will increasingly shift from foundational legislation to the practical enforcement of ethical standards and the promotion of AI as a tool for sustainable development and social equity.
policy · Effective Jan 1, 2024
policy · Effective Jan 1, 2023
central_coordinator
Lead agency for AI policy, strategy, and digital governance.
data_protection
Supervisory authority for data protection and privacy.
central_coordinator
Consumer protection and promotion of business competitiveness.
Oct 23, 2024 · news
Costa Rica launches 2024-2027 national AI strategy
Open source →Aug 9, 2024 · international_agreement
Latin American countries adopt sweeping AI declaration
Open source →Jul 10, 2023 · law_amended
Costa Rica uses ChatGPT to draft law to regulate AI
Open source →regulation · Effective Jan 1, 2022
act · Effective Jan 1, 2011
policy · Effective Jan 1, 2023