Colombia has not enacted a standalone AI statute as of August 2026. Its AI governance rests instead on CONPES 3975, a 2020 national policy document, a voluntary 2021 ethical framework published by the National Planning Department, and the Superintendencia de Industria y Comercio's existing data protection powers under the 2012 Habeas Data law. This guide explains each layer, what obligations actually bind an operator today, what penalties apply, and how the Colombian position compares to the EU AI Act's binding, risk-tiered regime.

Key takeaways

  • Colombia has no enacted, standalone AI statute as of August 2026. CONPES 3975 (approved November 2020) is a national policy document, not a binding law, setting strategic goals for AI adoption led by MinTIC and the National Planning Department (DNP).
  • DNP's Ethical Framework for Artificial Intelligence, published in 2021, sets voluntary principles for responsible AI design and use. It carries no penalty regime and creates no private right of action.
  • The Superintendencia de Industria y Comercio (SIC) already has enforcement powers over any AI system that processes personal data, under Law 1581 of 2012, the Habeas Data statute, independent of whether Colombia ever passes an AI-specific law.
  • Penalties for unlawful data processing under Law 1581 reach up to 2,000 times the monthly legal minimum wage, alongside SIC powers to order processing suspended or a database closed, but Colombia has no equivalent yet to the EU AI Act's turnover-based penalty regime.
  • An operator building a governance file to EU AI Act Article 26 standard already exceeds what Colombian law currently requires, which means EU-facing documentation travels well into the Colombian market with no separate compliance track needed.

The Colombian AI regulatory landscape in brief

Colombia is one of Latin America's largest digital economies and has positioned itself, through successive national development plans, as a regional leader on AI policy coordination. That policy leadership has translated into strategic documents and voluntary frameworks rather than into a binding statute. As of August 2026, the operative architecture in Colombia is a national policy document that predates most current AI agent deployments, a voluntary ethics framework, and direct application of Colombia's existing data protection law to any AI system that touches personal information.

This is a materially different position from the European Union, where Regulation (EU) 2024/1689 applies uniformly and directly as binding law across all member states, with graduated obligations tied to risk category and a dedicated penalty regime under Article 99. For an operator comparing the two markets, the practical consequence is not that Colombia is unregulated. It is that the enforceable floor in Colombia currently runs through general data protection law rather than through an AI-specific statute, and the strategic policy layer above that floor, while substantive, does not carry independent legal force.

CONPES 3975: the national policy foundation

Colombia's National Council for Economic and Social Policy (Consejo Nacional de Política Económica y Social, CONPES) approved Document 3975 in November 2020, titled the National Policy for Digital Transformation and Artificial Intelligence (Política Nacional para la Transformación Digital y la Inteligencia Artificial). CONPES documents are Colombia's mechanism for coordinating public investment and cross-ministerial policy; they are approved by the national planning body with cabinet-level participation but do not themselves create statutory obligations enforceable against private parties.

CONPES 3975 sets out strategic lines of action across several fronts relevant to AI operators: strengthening the conditions for AI development and adoption in both public and private sectors, building institutional capacity for AI governance, and establishing ethical principles for responsible AI use. Its lead implementing bodies are the Ministry of Information and Communications Technologies (MinTIC), which coordinates Colombia's broader digital transformation agenda, and the National Planning Department (DNP), which develops the policy's ethical and governance components. The document set a multi-year implementation horizon extending through the mid-2020s, and its influence is visible in subsequent government initiatives, including sector-specific AI adoption programmes and Colombia's participation in regional AI governance discussions through bodies such as the Inter-American Development Bank.

For an operator, the practical relevance of CONPES 3975 is directional rather than compliance-driving. It signals where Colombian regulators and ministries are likely to focus attention and where future binding rules, if enacted, are likely to originate. It does not itself require an operator to file documentation, undergo assessment, or meet a defined technical standard.

The Ethical Framework for Artificial Intelligence

Building on CONPES 3975, Colombia's National Planning Department published an Ethical Framework for Artificial Intelligence in 2021, developed with academic and multilateral input. The framework sets out voluntary principles covering transparency, fairness, human oversight, and accountability in AI system design and deployment, oriented initially toward public sector AI adoption but presented as a reference point for private sector actors as well.

The Ethical Framework functions similarly to early-stage AI ethics guidance published in other jurisdictions before binding legislation existed: it articulates the values a future statute would likely codify, without itself creating enforceable duties. Operators building governance documentation for the Colombian market can reasonably treat the framework's principles as a useful structuring reference, particularly because its emphasis on human oversight and transparency overlaps substantially with obligations that are binding elsewhere, including under Article 14 and Article 13 of the EU AI Act. An operator that has already built EU AI Act-aligned oversight documentation will find it maps cleanly onto the Colombian framework's expectations, even though the Colombian version carries no penalty for non-adoption.

The SIC: the practical enforcement floor

The Superintendencia de Industria y Comercio (SIC) is not new and does not depend on any future AI statute for its authority. The SIC has supervised the processing of personal data in Colombia under Law 1581 of 2012, the Habeas Data law, since shortly after its enactment, with an established track record of investigations and administrative sanctions against both public and private sector data controllers, known in Colombian law as responsables del tratamiento.

For AI operators, the SIC's relevance rests on a straightforward point: any AI agent that processes personal data, which covers the large majority of customer-facing chatbots, recommendation systems, and automated decision tools, engages the SIC's jurisdiction today, entirely independent of whether Colombia ever enacts AI-specific legislation. Law 1581 requires a lawful basis for processing, informed consent in most commercial contexts, and specific safeguards for sensitive data categories. Where an AI agent makes or substantially informs a decision about an individual, for example a credit pre-screening tool or an automated eligibility check, Colombian data protection principles around purpose limitation and data quality apply directly, in a manner functionally similar to the expectations GDPR Article 22 sets for automated decision-making in the EU.

The SIC has also exercised its broader consumer protection mandate over misleading or deceptive automated representations made to consumers, a jurisdiction analogous to the reasoning that held Air Canada responsible for its chatbot's representations in Moffatt v. Air Canada (BC Civil Resolution Tribunal, 2024): an operator in Colombia cannot disclaim responsibility for what its AI agent tells a customer by characterising the agent as a separate, unaccountable system.

Penalty exposure for operators in Colombia

Under Law 1581 of 2012, the SIC can impose administrative fines of up to 2,000 times the monthly legal minimum wage (salario mínimo mensual legal vigente) for violations of the data protection regime, alongside non-monetary remedial powers including orders to suspend specific processing activities or, in the most serious cases, to close the database involved. These powers apply directly to any AI deployment that processes personal data unlawfully, whether the underlying cause is inadequate consent, a security failure, or a discriminatory automated outcome that also breaches data protection principles.

Colombia has no equivalent yet to the EU AI Act's Article 99 turnover-based penalty regime, which reaches up to EUR 35 million or 7 percent of global annual turnover for the most serious violations. Should a future Colombian AI statute be enacted, drawing on the direction set by CONPES 3975, it would likely introduce a dedicated penalty structure specific to AI systems. As of August 2026, that layer remains prospective, and the SIC's existing Law 1581 powers represent the operative penalty exposure for AI deployments in Colombia.

Insurance and liability considerations for AI operators in Colombia

The market for AI-specific liability insurance available to operators in Colombia largely mirrors what is available through international brokers and reinsurers rather than developing a distinct domestic product line. Munich Re's aiSure product and Armilla's Lloyd's-backed AI coverage are accessible to Colombian enterprises through international broker channels, though underwriting for Latin American risk typically draws on more limited claims history than the European or North American markets these carriers have prioritised. As with other jurisdictions covered on this network, carriers assess governance documentation quality as part of underwriting, meaning an operator in Colombia with a well-documented risk assessment and human oversight practice, whether built to the DNP Ethical Framework or to a more demanding standard such as EU AI Act Article 26, is positioned for better underwriting terms than one without.

For operators active in both the Colombian and European markets, building governance documentation to the higher EU AI Act standard from the outset avoids maintaining two separate compliance tracks, since the EU-grade file already satisfies the lighter Colombian expectations set out in the Ethical Framework and the SIC's data protection requirements.

What operators in Colombia should do now

The absence of enacted AI-specific legislation does not mean Colombia is a low-governance environment for AI deployment, and the strategic direction set by CONPES 3975 signals where obligations are likely to tighten. The following steps represent the practical compliance priorities for an operator running AI agents in Colombia today.

First, treat the SIC's Law 1581 obligations as the binding floor, not an afterthought. Confirm a lawful basis for every AI system that processes personal data, document consent mechanisms, and apply the same rigor to automated decision-making that GDPR Article 22 principles would require in the EU, since Colombian data protection doctrine draws heavily on comparable European concepts.

Second, build governance documentation against the DNP Ethical Framework's principles, transparency, fairness, human oversight, and accountability, even though adoption is voluntary, because this is the direction Colombian policy is moving and the documentation doubles as evidence of reasonable care in any SIC investigation or civil claim.

Third, monitor the legislative process for any AI-specific bill advancing through the Colombian Congress, since CONPES 3975 explicitly anticipates future binding legislation, but do not treat the absence of an enacted statute as a reason to delay governance work that is already prudent under existing consumer protection and data protection law.

Fourth, for operators with any EU exposure, build to the higher EU AI Act Article 26 standard from the start. A governance file built to that standard is very likely to satisfy Colombia's current and near-future expectations without separate work, an approach explained in more general terms in the US-EU-UK AI liability comparison on this site.

Frequently asked questions

Does Colombia have a standalone AI law in 2026?

No. As of August 2026, Colombia has not enacted a standalone AI statute. Its AI governance rests on CONPES 3975 of 2020, a national policy document, which sets strategic direction rather than binding operator obligations. Several AI-specific bills have been debated in Congress, but none had been enacted as of this publication. The SIC and its existing data protection powers under Law 1581 of 2012 are the practical enforcement floor in the meantime.

What is CONPES 3975 and does it bind operators?

CONPES 3975 is a policy document approved in November 2020, titled the National Policy for Digital Transformation and Artificial Intelligence, led by MinTIC and the DNP. CONPES documents are policy instruments, not statutes; they guide public investment and coordination but do not themselves create enforceable obligations on private operators. Colombia's 2021 Ethical Framework for Artificial Intelligence, published by DNP, builds on CONPES 3975 with voluntary principles rather than binding rules.

What is the SIC's role in AI governance in Colombia?

The Superintendencia de Industria y Comercio (SIC) is Colombia's competition, consumer protection, and data protection authority under Law 1581 of 2012. Where an AI system processes personal data, the SIC already has enforcement powers regardless of whether Colombia enacts a dedicated AI statute. It can investigate complaints, order corrective measures, and impose administrative fines, making it the most concrete near-term enforcement contact for operators today.

What penalties apply to AI operators in Colombia?

Under Law 1581 of 2012, the SIC can impose administrative fines of up to 2,000 times the monthly legal minimum wage for unlawful processing of personal data, alongside orders to suspend processing or close a database. These penalties apply to any AI system that processes personal data unlawfully. Colombia has no equivalent yet to the EU AI Act's turnover-based penalty regime.

How does Colombia's approach compare to the EU AI Act?

Colombia's approach is data-protection-led rather than risk-tiered. The EU AI Act creates a binding, horizontal statute with graduated obligations, direct deployer duties, and turnover-based penalties up to EUR 35 million or 7 percent of global turnover. Colombia relies on a non-binding policy framework layered on existing Habeas Data enforcement not designed with AI in mind. EU-grade documentation exceeds what Colombian law currently requires.

References

  1. Consejo Nacional de Política Económica y Social (CONPES). Documento CONPES 3975: Política Nacional para la Transformación Digital y la Inteligencia Artificial, approved November 2020.
  2. Departamento Nacional de Planeación (DNP), Republic of Colombia. Marco Ético para la Inteligencia Artificial en Colombia, published 2021.
  3. Ley 1581 de 2012 (Colombia), Ley Estatutaria de Protección de Datos Personales (Habeas Data law).
  4. Superintendencia de Industria y Comercio (SIC). Data protection enforcement powers and administrative sanctions regime under Law 1581 of 2012.
  5. Regulation (EU) 2016/679 (GDPR), Article 22, referenced for comparative automated-decision-making principles.
  6. Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (EU AI Act). Official Journal of the European Union, 12 July 2024. Articles 26 (deployer obligations), 99 (penalties).
  7. Moffatt v. Air Canada, 2024 BCCRT 149 (British Columbia Civil Resolution Tribunal). Cited for the principle that an operator cannot disclaim responsibility for its automated system's representations to customers.
  8. Munich Re, aiSure AI performance insurance product. Munich Reinsurance Company.
  9. Armilla AI, AI performance guarantees and underwriting. Armilla AI Inc.