policy · Effective n/a
Sources:
IR regulates AI through National AI Organization (NAIO).
National AI Organization (NAIO)
Updated 60 days ago · 2 sources · confidence: medium
Overview
Iran's approach to artificial intelligence regulation has undergone a rapid transformation, moving from fragmented digital policies to a highly centralized, state-led strategic framework. In 2024 and 2025, the Islamic Republic accelerated its efforts to codify AI governance, primarily through the Supreme Council of the Cultural Revolution (SCCR) and the establishment of a dedicated National Artificial Intelligence Organization (NAIO). The overarching philosophy is rooted in the concept of 'AI Sovereignty,' which emphasizes the development of indigenous hardware, localized data processing, and Persian-language software ecosystems. This strategy is designed to reduce dependence on foreign technology platforms while ensuring that AI development aligns with national security interests and Islamic cultural values. Furthermore, the integration of AI is a core component of the country's Seventh National Development Plan, which seeks to modernize the economy through high-tech self-sufficiency. The maturity level of Iran's AI regulation is currently in a phase of intensive implementation. While earlier laws like the Computer Crimes Law (2009) and the Electronic Commerce Law (2004) provided a basic digital legal foundation, the 2024 National AI Document and the 2025 Law on Combating the Spread of Untrue News Content represent a more sophisticated, AI-specific regulatory era. These recent instruments focus on proactive governance, infrastructure control, and the mitigation of perceived 'psychological warfare' conducted through AI-generated content. The state views AI as a critical tool for both economic resilience under international sanctions and for maintaining social order, leading to a regulatory environment that prioritizes state oversight and national autonomy over individual digital rights.
Regulatory approach
Iran employs a hybrid regulatory approach that combines high-level horizontal strategic documents with sector-specific mandates. The primary instrument, the National AI Document, acts as a horizontal framework setting national goals, ethical principles, and institutional roles across all sectors of the economy. However, this is increasingly supplemented by prescriptive, binding laws such as the 2025 Law on Combating the Spread of Untrue News Content, which imposes specific technical requirements like mandatory watermarking for AI-generated media. The approach is predominantly top-down, with the Supreme Council of Cyberspace (SCC) and the NAIO wielding significant power to issue binding directives that bypass traditional legislative delays, allowing for rapid response to technological shifts. The regulatory philosophy is risk-based but defined through the lens of national and cultural security rather than consumer harm alone. High-risk AI applications are those that could impact public opinion, economic stability (e.g., financial market manipulation), or national security. Unlike the European Union's focus on individual privacy and transparency, Iran's risk assessment emphasizes the prevention of 'coordinated inauthentic behavior' and the spread of 'synthetic misinformation.' Consequently, the regulation is highly prescriptive regarding content verification and data localization, mandating that AI systems operating within the country adhere to strict state-defined 'Red Lines' and technical standards for data residency. This ensures that the state maintains a 'kill switch' or oversight capability over critical algorithmic processes. The governance of AI in Iran is centralized under the President and high-level councils. The National Artificial Intelligence Organization (NAIO), established in 2024, serves as the primary executive and regulatory body. It is tasked with infrastructure development, such as national GPU clusters, and the creation of technical standards. The NAIO operates under a Board of Trustees chaired by the President, ensuring that AI policy is integrated with national budget and security priorities. It acts as a bridge between technical research and state policy, coordinating with various ministries to implement the National AI Roadmap and managing the National AI Development Fund, which provides capital for strategic projects. The Supreme Council of Cyberspace (SCC) remains the highest policy-making body for all digital affairs, including AI. It defines the strategic 'Red Lines' and issues binding directives that other agencies must follow. Enforcement is carried out by the Cyber Police (FATA) and the National Committee for Content Verification (NCCV), which monitor digital platforms for compliance with content regulations. The judiciary has also established specialized courts for cybercrimes to handle legal disputes and prosecutions related to AI-generated disinformation or algorithmic manipulation, creating a comprehensive pipeline from policy creation to judicial enforcement. This structure ensures that AI development is not only technically sound but also politically and culturally aligned with the state's objectives.
Enforcement & penalties
Penalties for AI-related violations in Iran are severe and encompass administrative, financial, and criminal sanctions. Under the 2025 Law on Combating the Spread of Untrue News Content, 'High-Impact Content Producers' and platforms that fail to watermark AI-generated content or remove 'untrue' news face a graduated response strategy. These range from heavy fines and advertising bans to the throttling of internet bandwidth and total technical filtering (blocking) of the platform. For individuals, the deliberate dissemination of AI-generated 'synthetic misinformation' that harms national security or public order can lead to significant terms of imprisonment under the Islamic Penal Code and the Computer Crimes Law. The enforcement process is characterized by rapid response mechanisms. The National Committee for Content Verification (NCCV) can issue 'Correction Notices' that require immediate action, often within hours of a violation being identified. Failure to comply leads to administrative sanctions by the Communications Regulatory Authority (CRA). Furthermore, the 2009 Computer Crimes Law allows for the seizure of hardware and the dissolution of legal entities (companies) found to be negligent in securing their AI systems or intentionally using them for criminal purposes. Appeals are handled through specialized cybercrime branches of the judiciary, though state security considerations often take precedence in cases involving public tranquility and the prevention of social unrest.
Data protection
Iran does not currently have a single, comprehensive data protection law equivalent to the GDPR. Instead, data privacy is governed by a patchwork of regulations across different statutes. The Electronic Commerce Law (2004) provides early protections, requiring explicit consent for the processing of sensitive personal data such as health or racial information. However, these protections are often secondary to national security requirements. The 2024 National AI Document emphasizes 'Data Sovereignty,' which mandates that data generated by Iranian citizens be stored and processed within national borders. This localization requirement is a cornerstone of the state's strategy to protect against foreign surveillance and to fuel indigenous AI training models. Recent legislative efforts aim to formalize the rights of data subjects and the obligations of 'data controllers' through draft Personal Data Protection bills. However, in the current AI framework, the state maintains broad access rights to data for 'public interest' and security purposes. The NAIO is tasked with creating national data repositories, which involves consolidating data from various ministries into centralized hubs. While the National AI Document mentions ethical data stewardship, the practical implementation focuses on securing data as a national asset, with privacy protections being applied primarily to prevent unauthorized private-sector misuse rather than limiting state oversight or law enforcement access.
Sector-specific rules
Sectoral AI integration is a key pillar of Iran's Seventh National Development Plan, with specific rules emerging for critical industries. In the financial sector, the Central Bank of Iran (CBI) regulates the use of AI in banking and payment systems, focusing on fraud detection, credit scoring, and algorithmic stability. The Electronic Commerce Law provides the legal basis for 'Automated Transactions,' allowing AI to execute legally binding contracts. In healthcare, the Ministry of Health is developing guidelines for AI-assisted diagnostics, emphasizing that AI must serve as a decision-support tool rather than a replacement for licensed medical professionals, with strict requirements for the localization of patient health records to ensure bio-security. The energy sector, particularly oil and gas, is a priority for AI application to optimize production and manage infrastructure. The NAIO coordinates with the Ministry of Petroleum to deploy AI for predictive maintenance and resource management. In the media sector, the Islamic Republic of Iran Broadcasting (IRIB) and the Ministry of Culture and Islamic Guidance enforce strict rules on AI-generated content to ensure it aligns with cultural and religious standards. These sector-specific rules are often issued as 'by-laws' or 'directives' by the respective ministries under the umbrella of the National AI Document, ensuring a coordinated but specialized approach to deployment across the public and private sectors, with a heavy emphasis on industrial efficiency.
International alignment
Iran's AI regulatory framework is notably distinct from Western models like the EU AI Act. While it adopts some technical concepts—such as the need for transparency in AI-generated content—its primary alignment is with the principle of 'technological independence.' Iran does not officially adhere to OECD AI Principles, viewing them as reflective of Western geopolitical interests. Instead, it seeks alignment with other nations pursuing 'digital sovereignty' and explores cooperation within the BRICS framework or with regional partners to create alternative AI standards that bypass Western-led norms and international sanctions. This includes collaborative research on large language models that do not rely on Western datasets. Despite this divergence, the 2004 Electronic Commerce Law was originally modeled after UNCITRAL standards to facilitate international trade. However, the more recent 2024-2025 regulations prioritize domestic control and security over international interoperability. There is a clear effort to harmonize regulations with countries like Russia and China, particularly regarding data localization and the management of online content. Iran's international alignment is therefore strategic and selective, adopting international technical standards where necessary for trade but maintaining a strictly sovereign approach to governance, ethics, and security to protect its digital borders.
What's next
The future of AI regulation in Iran is expected to focus on the full operationalization of the National AI Organization (NAIO) and the expansion of the 'National Information Network' (NIN) to support AI infrastructure. Upcoming legislation is likely to include a dedicated 'Personal Data Protection and Preservation Act,' which has been in various stages of drafting and is now being accelerated to address the data-hungry nature of AI. Furthermore, the NAIO is expected to release a comprehensive 'AI Ethics Charter' that will provide more granular guidance on the religious and cultural boundaries of AI development and deployment, potentially setting a precedent for other Islamic nations. Another significant development will be the introduction of a 'Regulatory Sandbox' framework by the NAIO, intended to allow domestic startups to test AI applications in sectors like fintech and logistics under controlled conditions with relaxed regulatory requirements. As the 2025 Law on Combating the Spread of Untrue News Content enters its full enforcement phase, more detailed technical protocols for digital watermarking and the registration of 'High-Impact' AI models are expected. The government is also likely to introduce further fiscal incentives and tax breaks for 'Knowledge-Based AI Entities' to stimulate the domestic market and achieve its goal of becoming a top-ten global AI power by 2034, focusing on regional leadership in AI research.
policy · Effective n/a
Sources:
policy · Effective n/a
regulation · Effective n/a
Sources:
regulation · Effective n/a
central_coordinator
Centralized coordination of AI infrastructure, policy, and standards.
advisory
Highest policy-making body for digital and cyber affairs.
enforcement
Enforcement of computer crimes and digital content regulations.
sectoral
Technical regulation of telecommunications and digital platforms.
Dec 4, 2025 · international_agreement
Iran, Russia sign agreement to boost AI, cyber security cooperation
Open source →Apr 28, 2025 · international_agreement
BRICS+ sign declaration on AI governance
Open source →May 26, 2024 · law_amended
Iran's proposed Hijab and Chastity Bill tightens surveillance measures
Open source →Mar 16, 2024 · news
Iran's President wants new focus on AI
Open source →Jan 29, 2022 · guideline_issued
Iran plans to become a leading country in AI
Open source →