Peru enacted Law No. 31814 in 2023, a horizontal statute promoting responsible AI adoption, and followed it in 2024 with an implementing regulation that introduces a risk-based classification system for AI use. That combination makes Peru one of the small number of Latin American states with binding, AI-specific law on the books rather than a strategy document alone. This guide sets out what the law actually requires, how the risk tiers work, which authority enforces them, and how the regime compares to the EU AI Act and to Peru's separate data protection obligations.

Key takeaways

  • Peru's Congress approved Law No. 31814 in June 2023, a binding statute promoting the use of AI for economic and social development, built around principles including legality, precaution, human oversight, transparency, non-discrimination, and personal data protection.
  • A 2024 implementing regulation introduced a risk-tiered classification broadly comparable in shape to the EU AI Act, distinguishing unacceptable, high-risk, limited-risk, and minimal-risk AI uses, with heavier documentation and risk management duties attached to the higher tiers.
  • The Secretariat of Government and Digital Transformation (SGTD), under the Presidency of the Council of Ministers, is the lead coordinating body for AI policy, distinct from Peru's data protection authority, which continues to enforce Law No. 29733 for AI systems processing personal data.
  • Peru's regime is structurally closer to the EU AI Act than most Latin American peers because it is a genuine horizontal AI statute, but it is considerably lighter: no Article 99-style turnover-based penalty regime, no conformity assessment procedure, and no deployer-specific obligations comparable to Article 26.
  • An operator with an EU AI Act or ISO/IEC 42001-aligned compliance programme will, in most respects, exceed what Peruvian law currently requires, but should still treat the risk classification step and the separate data protection obligations as active compliance work, not a formality.

Background: Law 31814 as a genuine statute, not a strategy

Where a number of jurisdictions covered in this network, including Kenya and South Africa, have published AI strategies that set direction without creating enforceable obligations, Peru took a different path. Its Congress approved Law No. 31814, the Law that Promotes the Use of Artificial Intelligence in Favour of the Country's Economic and Social Development, in June 2023. Unlike a policy document, the law is binding legislation, published and in force, which places Peru among the first Latin American states to legislate specifically on AI rather than address it solely through general data protection or consumer law.

The law is deliberately principles-led rather than prescriptive in its original text. It sets out a list of guiding principles for AI use across the public and private sectors, including legality, precaution and prevention of harm, proportionality, non-discrimination, respect for human rights, transparency and explainability, human oversight, personal data protection, and a results-based, sustainability-oriented approach to AI adoption. On their own, these principles function more as interpretive guardrails than as a detailed compliance checklist, which is a common first-generation pattern: establish the statute and its principles first, then build out the operative detail through regulation.

The 2024 regulation: where the risk tiers appear

That operative detail arrived through the regulation implementing Law 31814, approved by supreme decree in 2024. The regulation is where Peru's framework becomes structurally comparable to the EU AI Act rather than a purely aspirational statute. It introduces a risk-based classification for AI systems, sorting uses into tiers that echo, in shape if not in stringency, the EU's unacceptable-risk, high-risk, limited-risk, and minimal-risk categories under Regulation (EU) 2024/1689.

AI uses classified as high-risk under the regulation face heavier obligations: documented risk management processes, records supporting the system's design and testing, and closer alignment with the transparency and human oversight principles set out in the parent law. Limited-risk uses face lighter, largely transparency-oriented duties, such as disclosing that a person is interacting with an AI system. The regulation applies across both public-sector and private-sector deployments, meaning a private company offering an AI-driven service in Peru falls within its scope on the same basis as a government agency doing so, subject to the specific use case's risk classification.

What the regulation does not yet include is anything resembling the EU AI Act's Article 99 turnover-based penalty regime or its Article 43 conformity assessment procedure for high-risk systems. Enforcement under Peru's framework currently rests more on the promotional and coordinating role of the designated authority than on a mature sanctions architecture, which is consistent with the law's stated purpose of promoting responsible AI adoption rather than primarily policing it.

Who enforces it: SGTD and the separate data protection track

The Secretariat of Government and Digital Transformation (Secretaria de Gobierno y Transformacion Digital, SGTD), operating under the Presidency of the Council of Ministers, is the lead body for AI policy coordination under Law 31814 and its regulation. The SGTD's role spans policy development, coordination across public entities, and oversight of the risk classification system, positioning it as Peru's closest equivalent to a national AI office, though its powers are considerably narrower than those of a dedicated market surveillance authority under the EU model.

Running in parallel, and independently of Law 31814, is Peru's data protection regime under Law No. 29733, the Personal Data Protection Law, enforced by Peru's national data protection authority under the Ministry of Justice. Any AI system processing personal data to make or materially influence a decision about an individual in Peru falls within the scope of this law regardless of whether it also triggers Law 31814's risk classification. Operators should treat these as two separate compliance tracks that happen to converge on the same AI system, not as a single unified regime, an arrangement that mirrors the pattern seen in several other pre-mature jurisdictions in this network, including Kenya and Nigeria, where a data protection authority remains the most concrete enforcement risk even after AI-specific legislation exists.

Comparison with the EU AI Act

Set against the EU AI Act, Peru's framework is unusual for the region in having a genuine horizontal AI statute at all, which puts it structurally ahead of many peers that rely on strategy documents or data protection law alone. Its risk-tiered regulation borrows the EU's basic shape: differentiated obligations scaled to risk, transparency duties for lower-risk uses, and heavier documentation for higher-risk ones. That said, the substantive depth is materially lighter. There is no Peruvian equivalent of the EU AI Act's Articles 9 through 17 technical documentation and quality management requirements, no conformity assessment procedure comparable to Article 43, no deployer-specific duties comparable to Article 26, and no penalty ceiling comparable to the EUR 35 million or 7 per cent of global turnover exposure under Article 99.

The practical implication for a global operator, consistent with the pattern seen across this network's jurisdiction guides, is that an EU AI Act or ISO/IEC 42001-aligned compliance programme will exceed what Peruvian law currently requires in almost every respect. The risk runs the other way for Peru-focused operators who have not built a compliance programme against any external benchmark: Law 31814's risk classification step and the separate data protection obligations under Law 29733 are both active, binding requirements today, not future ones, and should not be treated as lower priority simply because the penalty regime behind them is not yet EU-scale.

Practical implications for operators

Three steps are proportionate for an operator deploying AI in Peru in 2026. First, classify the AI system against the risk tiers set out in the regulation implementing Law 31814, and document that classification, since the tier determines which obligations, risk management documentation, transparency disclosures, or neither, actually apply. Second, treat Law No. 29733 compliance as a fully separate obligation whenever the AI system processes personal data, confirming registration and processing-basis requirements with Peru's data protection authority independently of any AI-specific classification work. Third, monitor SGTD publications and any further implementing guidance, since Peru's framework is still in an early operative phase and the authority is the most likely source of sector-specific clarifications as enforcement practice develops.

For the wider Latin American regulatory landscape this guide sits within, see the Brazil AI bill guide and the Chile AI regulation guide. For the EU deployer obligations that remain the highest-stringency benchmark against which any lighter-touch regime is measured, see the Article 26 deployer obligations guide on agentliability.eu. Operators assembling documentation evidence for cross-border AI governance programmes that include Peru may also find the Agent Certified methodology useful as a structured reference framework.

The gap to track. Peru's risk classification regulation is still building its enforcement track record, and no penalty case under Law 31814 comparable in scale to an EU AI Act fine has yet been publicly reported. A published enforcement decision, rather than a further regulation, is the development most likely to change how seriously operators should weigh this framework relative to Peru's separate and better-tested data protection enforcement.

Frequently asked questions

Does Peru have an enacted AI law in 2026?

Yes. Peru's Congress approved Law No. 31814, the Law that Promotes the Use of Artificial Intelligence for the Country's Economic and Social Development, in June 2023, and it was published shortly after. This made Peru one of the first Latin American states to enact a horizontal, binding AI statute rather than a policy document. A detailed implementing regulation followed in 2024, adding a risk-based classification system and concrete obligations.

Does Peru classify AI systems by risk level like the EU AI Act?

Yes, in structure though not in stringency. The regulation implementing Law 31814 introduces a risk-tiered approach broadly comparable in shape to the EU AI Act, distinguishing between AI uses that are unacceptable, high-risk, limited-risk, and minimal-risk, and attaching heavier obligations to systems in the higher tiers. The specific thresholds, sector coverage, and penalty regime are considerably lighter than the EU AI Act's Annex III categories and Article 99 turnover-based fines.

Which authority enforces AI regulation in Peru?

The Secretariat of Government and Digital Transformation (SGTD), part of the Presidency of the Council of Ministers, is the lead body for AI policy and coordination under Law 31814 and its regulation. For AI systems processing personal data, Peru's data protection authority under the Ministry of Justice retains its separate enforcement role under Law No. 29733.

How does Peru's AI law compare to the EU AI Act?

Peru's framework is a genuine horizontal AI statute, structurally closer to the EU AI Act than most Latin American peers. It is nonetheless considerably lighter: it lacks the EU AI Act's turnover-based penalty regime, conformity assessment procedures, and deployer-specific obligations. Peru's law is principles-led and promotion-oriented rather than a dense compliance and enforcement architecture.

Does Peru's data protection law apply to AI-driven decisions?

Yes. Law No. 29733, Peru's Personal Data Protection Law, governs the processing of personal data generally, including by AI systems, and is enforced by Peru's national data protection authority. An AI agent that processes personal data to make or influence a decision about an individual in Peru falls within scope regardless of whether Law 31814's AI-specific provisions also apply.

References

  1. Congress of the Republic of Peru. Law No. 31814, Ley que promueve el uso de la Inteligencia Artificial en favor del desarrollo economico y social del pais, approved June 2023.
  2. Presidency of the Council of Ministers (Peru). Regulation implementing Law No. 31814, approved by supreme decree, 2024, introducing risk-tiered AI classification.
  3. Secretariat of Government and Digital Transformation (Peru) (SGTD), Presidency of the Council of Ministers, lead coordinating authority for AI policy under Law 31814.
  4. Law No. 29733, Personal Data Protection Law (Peru), and Peru's national data protection authority under the Ministry of Justice.
  5. Regulation (EU) 2024/1689 of the European Parliament and of the Council (AI Act), for comparison, including Articles 9 to 17 (high-risk obligations), Article 26 (deployer obligations), Article 43 (conformity assessment), and Article 99 (penalties).
  6. International Organization for Standardization. ISO/IEC 42001:2023, Information technology, Artificial intelligence, Management system, referenced as a voluntary compliance benchmark exceeding Peru's current statutory requirements.