Colombia has not enacted a standalone AI statute as of August 2026. Its AI governance rests instead on CONPES 3975, a 2020 national policy document, a voluntary 2021 ethical framework published by the National Planning Department, and the Superintendencia de Industria y Comercio's existing data protection powers under the 2012 Habeas Data law. This guide explains each layer, what obligations actually bind an operator today, what penalties apply, and how the Colombian position compares to the EU AI Act's binding, risk-tiered regime.
Key takeaways
- Colombia has no enacted, standalone AI statute as of August 2026. CONPES 3975 is a national policy document, not a binding law, setting strategic goals for AI adoption led by MinTIC and the National Planning Department (DNP). Its approval date could not be confirmed at dnp.gov.co on 17 August 2026 and the November 2020 date previously given here has been withdrawn.
- DNP's Ethical Framework for Artificial Intelligence sets voluntary principles for responsible AI design and use. It carries no penalty regime and creates no private right of action. Its publication year could not be confirmed at dnp.gov.co on 17 August 2026 and the 2021 date previously given here has been withdrawn.
- The Superintendencia de Industria y Comercio (SIC) already has enforcement powers over any AI system that processes personal data, under Law 1581 of 2012, the Habeas Data statute, independent of whether Colombia ever passes an AI-specific law.
- Penalties for unlawful data processing under Law 1581 reach up to 2,000 times the monthly legal minimum wage, alongside SIC powers to order processing suspended or a database closed, but Colombia has no equivalent yet to the EU AI Act's turnover-based penalty regime.
- An operator building a governance file to EU AI Act Article 26 standard already exceeds what Colombian law currently requires, which means EU-facing documentation travels well into the Colombian market with no separate compliance track needed.
The Colombian AI regulatory landscape in brief
Colombia is one of Latin America's largest digital economies and has positioned itself, through successive national development plans, as a regional leader on AI policy coordination. That policy leadership has translated into strategic documents and voluntary frameworks rather than into a binding statute. As of August 2026, the operative architecture in Colombia is a national policy document that predates most current AI agent deployments, a voluntary ethics framework, and direct application of Colombia's existing data protection law to any AI system that touches personal information.
This is a materially different position from the European Union, where Regulation (EU) 2024/1689 applies uniformly and directly as binding law across all member states, with graduated obligations tied to risk category and a dedicated penalty regime under Article 99. For an operator comparing the two markets, the practical consequence is not that Colombia is unregulated. It is that the enforceable floor in Colombia currently runs through general data protection law rather than through an AI-specific statute, and the strategic policy layer above that floor, while substantive, does not carry independent legal force.
CONPES 3975: the national policy foundation
Colombia's National Council for Economic and Social Policy (Consejo Nacional de Política Económica y Social, CONPES) approved Document 3975, titled the National Policy for Digital Transformation and Artificial Intelligence (Política Nacional para la Transformación Digital y la Inteligencia Artificial). Sourcing note, 17 August 2026: the approval date could not be confirmed at dnp.gov.co, which could not be read from this session, and the November 2020 date previously given here has been withdrawn. A reader should also check dnp.gov.co for any later CONPES document on artificial intelligence, since this guide assumes 3975 is still the operative national policy and that assumption was not verified. CONPES documents are Colombia's mechanism for coordinating public investment and cross-ministerial policy; they are approved by the national planning body with cabinet-level participation but do not themselves create statutory obligations enforceable against private parties.
CONPES 3975 sets out strategic lines of action across several fronts relevant to AI operators: strengthening the conditions for AI development and adoption in both public and private sectors, building institutional capacity for AI governance, and establishing ethical principles for responsible AI use. Its lead implementing bodies are the Ministry of Information and Communications Technologies (MinTIC), which coordinates Colombia's broader digital transformation agenda, and the National Planning Department (DNP), which develops the policy's ethical and governance components. The document set a multi-year implementation horizon extending through the mid-2020s, and its influence is visible in subsequent government initiatives, including sector-specific AI adoption programmes and Colombia's participation in regional AI governance discussions through bodies such as the Inter-American Development Bank.
For an operator, the practical relevance of CONPES 3975 is directional rather than compliance-driving. It signals where Colombian regulators and ministries are likely to focus attention and where future binding rules, if enacted, are likely to originate. It does not itself require an operator to file documentation, undergo assessment, or meet a defined technical standard.
The Ethical Framework for Artificial Intelligence
Building on CONPES 3975, Colombia's National Planning Department published an Ethical Framework for Artificial Intelligence, developed with academic and multilateral input. Its publication year could not be confirmed at dnp.gov.co on 17 August 2026 and the 2021 date previously given has been withdrawn. The framework sets out voluntary principles covering transparency, fairness, human oversight, and accountability in AI system design and deployment, oriented initially toward public sector AI adoption but presented as a reference point for private sector actors as well.
The Ethical Framework functions similarly to early-stage AI ethics guidance published in other jurisdictions before binding legislation existed: it articulates the values a future statute would likely codify, without itself creating enforceable duties. Operators building governance documentation for the Colombian market can reasonably treat the framework's principles as a useful structuring reference, particularly because its emphasis on human oversight and transparency overlaps substantially with obligations that are binding elsewhere, including under Article 14 and Article 13 of the EU AI Act. An operator that has already built EU AI Act-aligned oversight documentation will find it maps cleanly onto the Colombian framework's expectations, even though the Colombian version carries no penalty for non-adoption.
The SIC: the practical enforcement floor
The Superintendencia de Industria y Comercio (SIC) is not new and does not depend on any future AI statute for its authority. The SIC has supervised the processing of personal data in Colombia under Law 1581 of 2012, the Habeas Data law, since shortly after its enactment, with an established track record of investigations and administrative sanctions against both public and private sector data controllers, known in Colombian law as responsables del tratamiento.
For AI operators, the SIC's relevance rests on a straightforward point: any AI agent that processes personal data, which covers the large majority of customer-facing chatbots, recommendation systems, and automated decision tools, engages the SIC's jurisdiction today, entirely independent of whether Colombia ever enacts AI-specific legislation. Law 1581 requires a lawful basis for processing, informed consent in most commercial contexts, and specific safeguards for sensitive data categories. Where an AI agent makes or substantially informs a decision about an individual, for example a credit pre-screening tool or an automated eligibility check, Colombian data protection principles around purpose limitation and data quality apply directly, in a manner functionally similar to the expectations GDPR Article 22 sets for automated decision-making in the EU.
The SIC also holds Colombia's consumer protection mandate, which on its face reaches misleading or deceptive representations made to consumers however they are generated. Sourcing note, 17 August 2026: an earlier version of this guide stated that the SIC has exercised that mandate over automated representations. No SIC decision confirming it could be read, and the claim has been withdrawn. The underlying principle is not novel: in Moffatt v. Air Canada, 2024 BCCRT 149, a tribunal held an airline responsible for what its chatbot told a customer and rejected the argument that the chatbot's statements were separable from the company's own. An operator in Colombia should assume the same reasoning is available to a Colombian authority, without assuming it has already been applied.
Penalty exposure for operators in Colombia
Under Law 1581 of 2012, the SIC can impose administrative fines of up to 2,000 times the monthly legal minimum wage (salario mínimo mensual legal vigente) for violations of the data protection regime, alongside non-monetary remedial powers including orders to suspend specific processing activities or, in the most serious cases, to close the database involved. These powers apply directly to any AI deployment that processes personal data unlawfully, whether the underlying cause is inadequate consent, a security failure, or a discriminatory automated outcome that also breaches data protection principles.
Colombia has no equivalent yet to the EU AI Act's Article 99 turnover-based penalty regime, which reaches up to EUR 35 million or 7 percent of global annual turnover for the most serious violations. Should a future Colombian AI statute be enacted, drawing on the direction set by CONPES 3975, it would likely introduce a dedicated penalty structure specific to AI systems. As of August 2026, that layer remains prospective, and the SIC's existing Law 1581 powers represent the operative penalty exposure for AI deployments in Colombia.
Insurance and liability considerations for AI operators in Colombia
The market for AI-specific liability insurance available to operators in Colombia largely mirrors what is available through international brokers and reinsurers rather than developing a distinct domestic product line. Munich Re's aiSure has been written with Mosaic Insurance since 26 February 2026 at an initial capacity of EUR, USD or CAD 15 million. Armilla is a Lloyd's coverholder whose Affirmative AI Liability Insurance is underwritten by certain underwriters at Lloyd's with limits up to USD 25 million per organisation, and Armilla states that coverage may not be available in all jurisdictions. Sourcing note, 17 August 2026: an earlier version of this guide stated that both products are accessible to Colombian enterprises through international broker channels. Neither carrier states that, and availability for a Colombian risk has to be confirmed with the underwriter rather than assumed. As with other jurisdictions covered on this network, carriers assess governance documentation quality as part of underwriting, meaning an operator in Colombia with a well-documented risk assessment and human oversight practice, whether built to the DNP Ethical Framework or to a more demanding standard such as EU AI Act Article 26, is positioned for better underwriting terms than one without.
For operators active in both the Colombian and European markets, building governance documentation to the higher EU AI Act standard from the outset avoids maintaining two separate compliance tracks, since the EU-grade file already satisfies the lighter Colombian expectations set out in the Ethical Framework and the SIC's data protection requirements.
What operators in Colombia should do now
The absence of enacted AI-specific legislation does not mean Colombia is a low-governance environment for AI deployment, and the strategic direction set by CONPES 3975 signals where obligations are likely to tighten. The following steps represent the practical compliance priorities for an operator running AI agents in Colombia today.
First, treat the SIC's Law 1581 obligations as the binding floor, not an afterthought. Confirm a lawful basis for every AI system that processes personal data, document consent mechanisms, and apply the same rigor to automated decision-making that GDPR Article 22 principles would require in the EU, since Colombian data protection doctrine draws heavily on comparable European concepts.
Second, build governance documentation against the DNP Ethical Framework's principles, transparency, fairness, human oversight, and accountability, even though adoption is voluntary, because this is the direction Colombian policy is moving and the documentation doubles as evidence of reasonable care in any SIC investigation or civil claim.
Third, monitor the legislative process for any AI-specific bill advancing through the Colombian Congress, since CONPES 3975 explicitly anticipates future binding legislation, but do not treat the absence of an enacted statute as a reason to delay governance work that is already prudent under existing consumer protection and data protection law.
Fourth, for operators with any EU exposure, build to the higher EU AI Act Article 26 standard from the start. A governance file built to that standard is very likely to satisfy Colombia's current and near-future expectations without separate work, an approach explained in more general terms in the US-EU-UK AI liability comparison on this site.
Frequently asked questions
Does Colombia have a standalone AI law in 2026?
No. As of August 2026, Colombia has not enacted a standalone AI statute. Its AI governance rests on CONPES 3975, a national policy document, which sets strategic direction rather than binding operator obligations. Several AI-specific bills have been debated in Congress, but none had been enacted as of this publication. The SIC and its existing data protection powers under Law 1581 of 2012 are the practical enforcement floor in the meantime.
What is CONPES 3975 and does it bind operators?
CONPES 3975 is a policy document titled the National Policy for Digital Transformation and Artificial Intelligence, led by MinTIC and the DNP. CONPES documents are policy instruments, not statutes; they guide public investment and coordination but do not themselves create enforceable obligations on private operators. Colombia's Ethical Framework for Artificial Intelligence, published by DNP, builds on CONPES 3975 with voluntary principles rather than binding rules. The approval dates for both documents could not be confirmed at dnp.gov.co on 17 August 2026 and have been withdrawn.
What is the SIC's role in AI governance in Colombia?
The Superintendencia de Industria y Comercio (SIC) is Colombia's competition, consumer protection, and data protection authority under Law 1581 of 2012. Where an AI system processes personal data, the SIC already has enforcement powers regardless of whether Colombia enacts a dedicated AI statute. It can investigate complaints, order corrective measures, and impose administrative fines, making it the most concrete near-term enforcement contact for operators today.
What penalties apply to AI operators in Colombia?
Under Law 1581 of 2012, the SIC can impose administrative fines of up to 2,000 times the monthly legal minimum wage for unlawful processing of personal data, alongside orders to suspend processing or close a database. These penalties apply to any AI system that processes personal data unlawfully. Colombia has no equivalent yet to the EU AI Act's turnover-based penalty regime.
How does Colombia's approach compare to the EU AI Act?
Colombia's approach is data-protection-led rather than risk-tiered. The EU AI Act creates a binding, horizontal statute with graduated obligations, direct deployer duties, and turnover-based penalties up to EUR 35 million or 7 percent of global turnover. Colombia relies on a non-binding policy framework layered on existing Habeas Data enforcement not designed with AI in mind. EU-grade documentation exceeds what Colombian law currently requires.
References
- Consejo Nacional de Política Económica y Social (CONPES). Documento CONPES 3975: Política Nacional para la Transformación Digital y la Inteligencia Artificial. Approval date could not be confirmed at dnp.gov.co on 17 August 2026 and the November 2020 date previously given has been withdrawn.
- Departamento Nacional de Planeación (DNP), Republic of Colombia. Marco Ético para la Inteligencia Artificial en Colombia. Publication year could not be confirmed at dnp.gov.co on 17 August 2026.
- Ley 1581 de 2012 (Colombia), Ley Estatutaria de Protección de Datos Personales (Habeas Data law).
- Superintendencia de Industria y Comercio (SIC). Data protection enforcement powers and administrative sanctions regime under Law 1581 of 2012.
- Regulation (EU) 2016/679 (GDPR), Article 22, referenced for comparative automated-decision-making principles.
- Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (EU AI Act). Official Journal of the European Union, 12 July 2024. Articles 26 (deployer obligations), 99 (penalties).
- Moffatt v. Air Canada, 2024 BCCRT 149 (British Columbia Civil Resolution Tribunal). Cited for the principle that an operator cannot disclaim responsibility for its automated system's representations to customers.
- Munich Re aiSure, written with Mosaic Insurance since 26 February 2026 at an initial capacity of EUR, USD or CAD 15 million.
- Armilla, a Lloyd's coverholder. Affirmative AI Liability Insurance underwritten by certain underwriters at Lloyd's, limits up to USD 25 million per organisation. Armilla states that coverage may not be available in all jurisdictions.