Overview
Uzbekistan has rapidly accelerated its artificial intelligence (AI) regulatory landscape, moving from broad digitization initiatives under the "Digital Uzbekistan 2030" program to a highly specialized and aggressive national AI strategy. The country's regulatory philosophy is characterized by a state-led, top-down approach that views AI as a critical engine for economic diversification and administrative efficiency. The primary objective is to position Uzbekistan as a regional technological hub in Central Asia, with the government setting ambitious quantitative targets for AI-driven revenue, public service automation, and international index rankings. This approach is codified in the landmark Presidential Resolution PP-358, which serves as the master blueprint for the nation's AI ecosystem through the end of the decade. The maturity of Uzbekistan's AI framework is currently in a transitional phase, shifting from policy formulation to active infrastructure deployment. While early efforts (circa 2021) focused on creating experimental conditions and research pilot programs, the current 2024–2030 strategy mandates the creation of foundational assets such as a national Big Data database and specialized high-performance computing clusters. The government's philosophy balances the need for rapid innovation with a structured legal framework, emphasizing that AI development must align with national interests, economic security, and the preservation of social values. This involves a heavy emphasis on "sovereign AI" capabilities, including the development of large language models and datasets specifically tailored to the Uzbek language and local cultural context. The state also aims to improve its position in the Government AI Readiness Index, targeting a spot in the top 50 globally by 2030.
Regulatory approach
Uzbekistan employs a hybrid regulatory approach that combines horizontal national strategies with targeted sectoral mandates. The framework is predominantly prescriptive and binding, driven by Presidential Resolutions and Cabinet of Ministers' decrees that carry the force of law. Unlike the more decentralized or market-led approaches seen in some Western jurisdictions, Uzbekistan's model is highly centralized under the Ministry of Digital Technologies. This centralization ensures that AI adoption across various ministries—from agriculture to finance—remains synchronized with the national infrastructure and data standards. The regulatory environment is also characterized by the use of "Special Regimes" or sandboxes, which allow for the experimental implementation of AI technologies under supervised conditions to identify legal gaps before full-scale rollout. The approach is increasingly risk-aware, though not yet as granularly risk-classified as the European Union's AI Act. Instead, Uzbekistan focuses on "priority sectors" where AI impact is deemed highest for the national economy. The regulatory logic follows a path of "infrastructure first, regulation second," where the government prioritizes building the technical capacity for AI (data, compute, and human capital) while simultaneously drafting the ethical and legal standards that will govern its use. This includes a commitment to harmonizing national standards with international practices, particularly in areas of data privacy, algorithmic transparency, and the prevention of bias in automated decision-making systems. The strategy explicitly calls for the development of a legal framework that provides "responsible AI" while minimizing barriers to entry for domestic startups and fostering a competitive digital economy. The Ministry of Digital Technologies of the Republic of Uzbekistan is the primary executive body responsible for the implementation of AI policy. It holds a broad mandate to coordinate digital transformation across all government agencies, manage the national data infrastructure, and represent Uzbekistan in international digital forums. Under the 2030 Strategy, the Ministry is tasked with overseeing the newly created Center for Development of Artificial Intelligence and Digital Economy, which acts as the technical and research arm for AI implementation. This center is responsible for conducting R&D, developing ethical guidelines, and assisting other ministries in deploying AI solutions within their specific domains. Oversight and high-level coordination are provided by the Coordination Commission for the Digital Uzbekistan 2030 Strategy. This commission monitors the progress of AI projects, ensures inter-agency cooperation, and evaluates the achievement of the strategy's key performance indicators (KPIs). For enforcement related to data and telecommunications, the State Inspectorate for Supervision in the Sphere of Informatization and Telecommunications (Uzkomnazorat) plays a critical role. It has the power to audit AI systems for compliance with data protection laws and can issue sanctions or restrict access to services that violate national regulations regarding data processing or cybersecurity. The interaction between these bodies ensures that AI development is not only technically sound but also legally compliant and strategically aligned with the nation's broader economic goals.
Enforcement & penalties
Enforcement of AI-related regulations in Uzbekistan is primarily managed through administrative and civil channels, with criminal liability reserved for severe breaches of data security or unauthorized access to sensitive systems. Under the Code of Administrative Responsibility, violations of personal data processing rules—which are central to AI operations—can result in significant fines for both individuals and officials. If an AI system is found to be operating in violation of the "Special Regime" (sandbox) rules, the participating entity may be expelled from the program, lose its tax incentives, and be barred from future government contracts. The government also utilizes "soft enforcement" through the mandatory registration of AI systems in national databases, where failure to comply can lead to the suspension of the service. The 2030 Strategy introduces a more rigorous monitoring mechanism where the Ministry of Digital Technologies and the Coordination Commission conduct regular audits of AI implementation in priority sectors. If a ministry or state-owned enterprise fails to meet the AI adoption targets or violates the prescribed technical standards, it may face budgetary repercussions or administrative penalties for its leadership. Furthermore, the Law on Cybersecurity provides a framework for penalizing the negligent deployment of AI that leads to the compromise of critical information infrastructure. Appeals against enforcement actions are typically handled through the administrative court system, though the government is currently exploring specialized arbitration mechanisms for high-tech disputes within the IT Park framework to provide a more efficient resolution process for international investors.
Data protection
The data protection framework in Uzbekistan is anchored by the Law "On Personal Data" (ZRU-547), which shares several principles with the EU's GDPR, such as the requirements for purpose limitation, data minimization, and the right of the data subject to be informed. However, a defining feature of the Uzbek framework is its strict data localization requirement (Article 27-1), which mandates that the personal data of Uzbek citizens must be physically processed and stored on servers located within the Republic of Uzbekistan. This has profound implications for AI developers, as it necessitates the use of local cloud infrastructure for training models on domestic datasets and complicates the use of international AI service providers that do not have a local presence. For AI applications, the framework requires explicit consent for the processing of sensitive data, and the 2030 Strategy emphasizes the creation of "National Big Data Collections." These collections are intended to provide a structured and legal way for AI developers to access anonymized state data. The government is also working on guidelines for data de-identification to ensure that the use of large-scale datasets for AI training does not compromise individual privacy. Compliance is monitored by Uzkomnazorat, which has the authority to block websites or platforms that fail to comply with localization or data processing standards, a power that has been exercised against major international social media and tech platforms in the past. This localization-centric approach is designed to ensure digital sovereignty and protect the privacy of citizens in an increasingly data-driven global economy.
Sector-specific rules
Uzbekistan's AI strategy identifies several priority sectors with tailored implementation rules. In the Banking and Finance sector, the Central Bank of Uzbekistan oversees the use of AI for credit scoring and fraud detection. Regulations emphasize the need for "explainability" in automated credit decisions to prevent discrimination and ensure financial stability. Financial institutions are encouraged to use AI to reduce the "shadow economy" by monitoring suspicious transactions, but they must do so within the strict reporting frameworks established by the Department for Combating Economic Crimes. In the Healthcare sector, the Ministry of Health is leading the integration of AI for medical imaging and diagnostics. The focus here is on clinical validation and the security of patient records. AI systems used in medical settings must undergo specific certification processes to ensure accuracy and safety. In Agriculture, the focus is on precision farming and resource management, with rules centered on the integration of satellite data and IoT sensors with AI platforms. The government provides subsidies and interest-free loans for agricultural enterprises that adopt these technologies, provided they comply with the technical standards set by the Ministry of Agriculture and the Ministry of Digital Technologies. Additionally, the energy sector is exploring AI for grid optimization and demand forecasting, while the judicial system is piloting AI tools for document analysis and legal research, all under the supervision of their respective regulatory bodies to ensure that sector-specific risks are adequately managed.
International alignment
Uzbekistan is actively seeking to align its AI regulations with international standards to facilitate technological exchange and attract foreign investment. The 2030 Strategy explicitly mentions the goal of harmonizing national standards with those of the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). Furthermore, Uzbekistan has expressed commitment to the UNESCO Recommendation on the Ethics of Artificial Intelligence, which serves as a foundational document for the ethical guidelines currently being developed by the Center for Development of AI and Digital Economy. While not a member of the European Union, Uzbekistan monitors the EU AI Act as a benchmark for risk-based regulation, particularly regarding high-risk AI applications in public services and law enforcement. Regionally, Uzbekistan participates in AI-related initiatives within the Commonwealth of Independent States (CIS) and the Shanghai Cooperation Organisation (SCO), focusing on cross-border data flows and joint research projects. The country's ambition to reach the top 50 in the Government AI Readiness Index drives its alignment with the OECD's AI Principles, particularly those concerning investment in R&D, fostering a digital ecosystem, and building human capacity. This international outlook is balanced with the need for national digital sovereignty, ensuring that while the country adopts global best practices, it maintains control over its critical data and technological infrastructure.
What's next
The next two years will be critical for the expansion of Uzbekistan's AI legal framework. By May 1, 2025, the government expects to have the national Big Data database fully operational, which will be accompanied by new regulations governing data access rights for private sector AI developers. This will likely include a tiered access system where startups can apply for access to specific government datasets under strict ethical and security protocols. Additionally, by May 1, 2026, the launch of the national high-performance computing infrastructure will necessitate new rules regarding the shared use of state-funded compute resources. Legislatively, there are plans to introduce a formal Code of AI Ethics, which will move from a voluntary guideline to a mandatory requirement for any AI system deployed in the public sector or used for processing citizen data. The government is also considering amendments to the Law on Personal Data to better address the challenges of generative AI and synthetic data. As the $50 million interest-free loan facility from the Reconstruction and Development Fund begins its rollout in 2025, new financial oversight regulations will be established to ensure that AI investments yield the targeted economic returns and social benefits outlined in the 2030 Strategy. These developments signal a shift from foundational policy-making to a more mature, implementation-focused regulatory environment that seeks to balance rapid technological growth with robust legal and ethical safeguards.