Artificial intelligence in Colombia: Regulatory developments and business considerations
During our September 17th, 2026 periodic call with MSI member firms in Latin America, we discussed among other matters, the development of artificial intelligence regulation across the region. Several countries—including Argentina, Brazil, Chile, Costa Rica, Ecuador, Mexico, Panama, Peru, and Uruguay—have introduced legislative initiatives addressing the protection of software and IT services, as well as the responsible development and use of artificial intelligence.
Colombia has been particularly active in this area. Since 2020, members of both the House of Representatives and the Senate have introduced bills concerning artificial intelligence, including initiatives that have remained under discussion since 2023. This legislative process continued with a bill filed on July 21, entitled “By means of which artificial intelligence is regulated in Colombia to guarantee its ethical and responsible development and other provisions are enacted.”
The proposal responds to the need for a comprehensive framework capable of balancing technological development with the protection of fundamental rights. AI systems can generate significant economic and social benefits but they may also affect privacy, equality, freedom, security, and the right to non-discrimination. The bill therefore seeks to establish safeguards based on transparency, human oversight, accountability, cybersecurity, and physical safety throughout an AI system’s life cycle. It addresses also specific concerns such as the use of copyrighted works, the allocation of responsibility for AI-generated outputs, and the use of AI to impersonate individuals or falsify their identity.
At the same time, the initiative is not limited to imposing restrictions. It aims to create legal certainty for developers, suppliers, users, and investors, while encouraging research and the responsible adoption of AI. Regulatory sandboxes would allow companies to test and validate new solutions in controlled environments under public supervision.
In developing this framework, Colombia has drawn on leading international and regional standards, particularly the European Union Artificial Intelligence Act and Chile’s AI Bill, both of which adopt a risk-based approach that imposes different obligations depending on the level of risk presented by an AI system. The proposal is also aligned with OECD and UNESCO principles, emphasizing transparency, accountability, human oversight, privacy protection, non-discrimination, and responsible innovation.
From a business perspective, the bill has a broad scope. It would apply to any company involved in the design, development, training, testing, validation, deployment, operation, monitoring, maintenance, commercialization, importation, distribution, or use of an AI system whenever that system produces effects in Colombia or processes data relating to Colombian individuals or entities. Accordingly, the legislation may affect not only technology developers, but also companies in traditional industries that acquire or use third-party AI tools in their operations.
Compliance would begin with identifying the AI systems used by the organization and determining the risk category applicable to each one. Because the proposal distinguishes among prohibited, high-risk, limited-risk, and low-risk systems, the duties imposed on a company would depend on the nature, purpose, and potential impact of the technology.
Businesses may also face administrative, civil, or criminal liability for harm caused through AI. In addition, where implementation may transform or displace existing job functions, employers would be expected to adopt training, reassignment, or workforce-transition measures. Companies with AI systems already in operation would therefore need to review their documentation, internal controls, governance arrangements, and risk-management procedures.
Although the bill remains part of an evolving legislative process, its direction is clear: organizations operating in or affecting the Colombian market should prepare for greater scrutiny of AI-related risks, data practices, transparency measures, and internal accountability.
A prudent first step is to map existing and planned AI uses, assess their potential risk classification, assign responsibility for oversight, and develop a compliance roadmap. Early preparation will not only reduce regulatory exposure but may also position companies to benefit from responsible-innovation programs, public-private initiatives, and future incentives.