Peru has a binding AI statute and, since September 2025, a regulation with teeth in it. Law No. 31814 was passed by Congress on 13 June 2023 and published on 5 July 2023. Its implementing regulation, approved by Decreto Supremo No. 115-2025-PCM and published on 9 September 2025, sorts AI uses into three categories, enumerates prohibited practices, and sets staged compliance deadlines by sector. The first of those deadlines falls in September 2026. This guide sets out what the regulation actually requires, what it requires only of the state, where the enforcement actually sits, and what a private operator in Peru should be doing now.

Key takeaways

  • Law No. 31814, the law promoting the use of artificial intelligence for the country's economic and social development, was approved by Congress on 13 June 2023, promulgated on 4 July and published in El Peruano on 5 July 2023.
  • The implementing regulation is Decreto Supremo No. 115-2025-PCM, published 9 September 2025: six titles, thirty six articles and six final complementary provisions. Most of it entered into force ninety business days after publication.
  • There are three risk categories, not four. Article 22 sets uso indebido, improper use, which is prohibited outright and enumerated in Article 23; uso de riesgo alto, high-risk use, enumerated in Article 24; and riesgo aceptable, the residual category for everything else. The EU's limited-risk and minimal-risk labels do not appear.
  • The obligations split sharply between state and private sector. Risk management under Article 29(a) and the impact assessment under Article 30.1 bind public administration entities. For private developers and implementers the impact assessment is expressly voluntary under Article 32.1, and the binding duties are the Article 31.1 record and the Article 25 algorithmic transparency duty.
  • The deadlines are live. Private operators in health, education, justice, security, economy and finance have one year from the regulation's entry into force, which falls in September 2026. Transport, commerce and labour have two years, production, agriculture, energy and mining three, everything else four. Small enterprises get two years and microenterprises three.
  • There is no AI-specific fine, but there is a referral architecture. The SGTD reports non-compliant officials to the Contraloria General and refers suspected intellectual property, data protection or fundamental rights violations to the competent sanctioning authorities, and affected persons can complain to INDECOPI, the cybercrime police division or the data protection authority.

Law 31814: a genuine statute, and what is actually in it

Where several jurisdictions in this network have published AI strategies that set direction without creating enforceable obligations, Peru legislated. Congress approved Law No. 31814 in Lima on 13 June 2023. It was promulgated on 4 July and published in El Peruano on Wednesday 5 July 2023, placing Peru among the first Latin American states to legislate specifically on AI rather than address it only through data protection or consumer law.

The Law is short and principles-led. Its Preliminary Title sets six principles: risk-based security standards; a multi-stakeholder approach; internet governance; the digital society; ethical development for responsible AI; and privacy of artificial intelligence. An earlier version of this guide listed a different set, including legality, precaution, proportionality, non-discrimination, human oversight and transparency, and attributed them to the Law. Those words do not appear in it. Several of them do appear in Article 7 of the 2025 regulation, which is where the guide's list appears to have drifted in from.

Article 4 of the Law, headed Autoridad Nacional, designates the Presidency of the Council of Ministers, acting through the Secretariat of Government and Digital Transformation, as the national technical and normative authority responsible for directing, evaluating and supervising the use and promotion of AI and emerging technologies. That is a stronger designation than the coordinating role an earlier version of this guide described.

One drafting detail matters for anyone reading the Law alone. Article 3(b) of the Law defines an AI system as an electro-mechanical system. Article 6(j) of the 2025 regulation replaces that with the OECD-style formulation: a machine-based system that, for explicit or implicit objectives, infers from the input it receives how to generate outputs. An operator applying the statutory definition without the regulation would be applying the wrong one.

The 2025 regulation: three categories, and who they bind

The operative detail arrived through Decreto Supremo No. 115-2025-PCM, signed on 8 September 2025 and published on 9 September 2025, countersigned by the President of the Council of Ministers and the Ministers of Education, Production, and Justice and Human Rights. It runs to six titles, thirty six articles and six final complementary provisions. Most of it entered into force ninety business days after publication; the First, Second, Fourth and Fifth final complementary provisions took effect the day after.

Article 22 sets the classification. Uso indebido covers any AI system used to have an irreversible, significant and negative impact on fundamental rights or on people's wellbeing, in any circumstance, and such use is prohibited. Uso de riesgo alto covers systems that may be used subject to defined conditions and controls. Everything not caught by Articles 23 or 24 is riesgo aceptable. Three categories, not four, and the residual tier carries no dedicated obligations.

Article 23 enumerates the prohibited uses, and the list is worth reading in full rather than summarising: manipulative or subliminal techniques, and exploitation of cognitive, emotional or socioeconomic vulnerabilities; autonomous lethal capability in the civil sphere; mass surveillance without legal basis; biometric inference of race, ethnicity, political opinions, union membership, religious or philosophical beliefs, sex life or sexual orientation, and discriminatory profiling; real-time biometric identification for categorisation in public spaces, with carve-outs for digital identity authentication and preliminary investigation of enumerated serious crimes; and predictive policing based on personality profiling.

Article 24 enumerates high-risk uses: critical national assets supporting essential services including energy, telecommunications, health, transport, water and banking; educational assessment of minors; hiring, evaluation, contracting, dismissal and the setting of working conditions; access to and prioritisation of social programmes; credit scoring, with fraud detection excepted; access to health services; clinical triage, diagnosis, prognosis and processing of electronic health records; emotion inference in workplaces and schools; and a catch-all.

Articles 23.3 and 24.2 give any developer or implementer a route to ask the SGTD for a determination of whether a given system falls into prohibited use or high risk. For a borderline system, that is the cheapest way to resolve the question.

What a private operator actually has to do

The regulation applies to the private sector. Article 3 covers public administration entities, state-owned enterprises, and organisations of the private sector, civil society, citizens and academia within the National Digital Transformation System. Article 4 excludes purely personal use and national defence and security use that meets the Article 7 principles.

But the duties are not symmetrical, and this is where the earlier version of this guide was misleading. Risk management as a named obligation under Article 29(a) binds public administration entities. The high-risk impact assessment is mandatory for the public sector under Article 30.1 and expressly voluntary for the private sector under Article 32.1, with a three-year retention rule under Article 32.3 if one is carried out.

What binds a private developer or implementer of a high-risk system is Article 31.1: maintain an updated and accessible record, taking a preventive approach, of the system's operating principles, the data sources used, the logic of the algorithm, and the expected social and ethical impacts. Alongside it sits the Article 25 algorithmic transparency duty, which attaches to high-risk systems, and the Article 31.4 human oversight duty for systems used in health, education, justice, finance and access to basic programmes and services.

Note what this means for the guide's earlier framing. Article 25 transparency is a high-risk obligation, not a light-touch duty attaching to a limited-risk tier that does not exist. And a private operator that documents only design and testing evidence has not met Article 31.1, which asks for something different: principles, sources, logic and expected impacts.

Public entities carry a further obligation the private sector does not. Article 28.2 makes NTP-ISO/IEC 42001:2025 mandatory for public entities developing AI systems, and the Sixth Final Complementary Provision makes NTP-ISO/IEC 27002 and NTP-ISO 31000 obligatory for them. For a public-sector deployment in Peru, ISO/IEC 42001 is not a voluntary benchmark that exceeds the law; it is the law.

The deadlines, which are closer than they look

The First Final Complementary Provision took effect the day after publication and starts the clock. Private developers and implementers must comply with Article 25 and Title VI Chapter II within one year for health, education, justice, security, economy and finance; two years for transport, commerce and labour; three years for production, agriculture, energy and mining; and four years for everything else. Small enterprises, with annual sales between 150 and 1,700 UIT, get two years, and microenterprises up to 150 UIT get three.

Public bodies run on their own schedule: one year for the three branches of government and autonomous constitutional bodies, two years for EsSalud, regional governments, public universities and state enterprises, three years for Type A, B and C local governments, and optional participation for Types D to G.

A Peruvian healthcare provider or fintech reading this in August 2026 has weeks, not years.

Enforcement: no AI fine, but a referral architecture

Neither Law 31814 nor Decreto Supremo No. 115-2025-PCM creates an AI-specific administrative fine, an infraction table or a turnover-based ceiling. Saying that there is therefore no enforcement would be wrong, and an earlier version of this guide came close to it.

What the regulation builds instead is a set of referral routes. Article 34.1 has the SGTD report non-compliant public officials to the Contraloria General de la Republica. Article 34.2 has it refer suspected intellectual property, data protection or fundamental rights violations to the competent authorities for inspection and sanction. Article 26.2 routes data protection breaches to the sanctions regime under Law No. 29733 and its regulation. Article 36.2 lets any affected person, including minors through guardians, complain to INDECOPI, the cybercrime division of the national police, or the national data protection authority. The Third Final Complementary Provision creates gob.pe/iaperu as the official AI channel.

The SGTD's own powers under Article 8 of the regulation include issuing binding opinions on the scope and interpretation of the AI rules, approving guidelines and standards, supervising compliance, and reporting annually to Congress's Science, Innovation and Technology Committee by the last business day of March.

The data protection track, which is where the fines are

Running in parallel is Peru's data protection regime under Law No. 29733, enforced by the Autoridad Nacional de Proteccion de Datos Personales of the Ministry of Justice and Human Rights. Article 26.1 of the AI regulation names that authority directly.

The important development here, which an earlier version of this guide missed entirely, is that the old implementing regulation has been replaced. Decreto Supremo No. 016-2024-JUS, approving the new regulation of Law No. 29733, was signed on 29 November 2024 and published as a special supplement in El Peruano on 30 November 2024. It repeals Decreto Supremo No. 003-2013-JUS and entered into force 120 calendar days after publication, at the end of March 2025. It carries a full Title III on infractions and sanctions, with inspection powers, minor, serious and very serious grading fined under Article 39 of the Law, and coercive fines escalating to a cap of 100 UIT.

For a private operator, this is the regime that actually imposes fines on AI-driven processing in Peru. The AI regulation's own enforcement runs through referral; the data protection regulation's runs through a sanctions title.

Comparison with the EU AI Act

Set against the EU AI Act, Peru's framework is unusual for the region in having both a horizontal statute and a detailed implementing regulation with an enumerated prohibited-use list. Its structure borrows the EU's logic: prohibited practices, a high-risk list, transparency and human oversight duties.

The substantive depth is lighter in the ways that matter to an operator. There is no conformity assessment procedure comparable to Article 43, no notified body architecture, and no penalty ceiling comparable to the EUR 35 million or 7 per cent of global turnover under Article 99. The private-sector impact assessment is voluntary where the EU's fundamental rights impact assessment under Article 27 is not.

The practical implication is narrower than the claim an earlier version of this guide made. An EU AI Act or ISO/IEC 42001-aligned programme will cover most of what Peru asks of a private operator, but not all of it: the Article 31.1 record has a specific content list, and the classification and consultation steps under Articles 23.3 and 24.2 have no EU equivalent. For a public-sector deployment the relationship reverses, because NTP-ISO/IEC 42001:2025 is mandatory there.

Practical implications for operators

Five steps are proportionate for an operator deploying AI in Peru in 2026. First, work out which of the three Article 22 categories each system falls into, checking Article 23 and Article 24 by their enumerated lists rather than by analogy to the EU annexes. Second, find your sector's deadline in the First Final Complementary Provision; if you are in health, education, justice, security, economy or finance, it falls in September 2026. Third, for each high-risk system, build the Article 31.1 record: operating principles, data sources, algorithmic logic, expected social and ethical impacts, kept updated and accessible. Fourth, treat compliance with Law No. 29733 and its 2024 regulation as a separate and more consequential workstream wherever personal data is processed, because that is where the sanctions are. Fifth, if a classification is genuinely borderline, use the Article 23.3 or 24.2 consultation route rather than guessing.

For the wider Latin American regulatory landscape this guide sits within, see the Brazil AI bill guide and the Chile AI regulation guide. For the EU deployer obligations that remain the highest-stringency benchmark against which any lighter-touch regime is measured, see the Article 26 deployer obligations guide on agentliability.eu.

The gap to track. The Second Final Complementary Provision required the SGTD to approve ethical guidelines (Lineamientos Eticos) within 180 business days of publication, which falls in mid-2026. Whether those guidelines have issued, and what they say about the Article 31.1 record, is the single most useful thing to monitor on this framework. The other is the first referral under Article 34.2, since that is how enforcement will actually arrive.

Frequently asked questions

Does Peru have an enacted AI law in 2026?

Yes. Congress approved Law No. 31814, the law promoting the use of artificial intelligence for the country's economic and social development, on 13 June 2023. It was promulgated on 4 July and published in El Peruano on 5 July 2023. Its implementing regulation was approved by Decreto Supremo No. 115-2025-PCM, signed 8 September 2025 and published 9 September 2025, running to six titles, thirty six articles and six final complementary provisions. Most of the regulation entered into force ninety business days after publication.

How does Peru classify AI systems by risk?

Article 22 of Decreto Supremo No. 115-2025-PCM sets three categories, not four. Uso indebido, improper use, covers any AI system used to have an irreversible, significant and negative impact on fundamental rights or wellbeing, and is prohibited; the prohibited practices are enumerated in Article 23. Uso de riesgo alto, high-risk use, is enumerated in Article 24 and may be used subject to conditions and controls. Everything not caught by Articles 23 or 24 is riesgo aceptable, acceptable risk, and carries no dedicated obligations. The EU's limited-risk and minimal-risk labels do not appear in the Peruvian regulation.

What must a private operator actually do under Peru's AI regulation?

For a high-risk system, Article 31.1 requires an updated and accessible record, taking a preventive approach, of the system's operating principles, the data sources used, the logic of the algorithm, and the expected social and ethical impacts. Article 25 imposes algorithmic transparency for high-risk systems, and Article 31.4 requires human oversight where the system is used in health, education, justice, finance or access to basic programmes and services. The impact assessment is mandatory for public administration entities under Article 30.1 but expressly voluntary for the private sector under Article 32.1, with a three-year retention rule under Article 32.3 if one is carried out.

When do Peru's AI compliance deadlines fall?

The First Final Complementary Provision of Decreto Supremo No. 115-2025-PCM staggers compliance by sector. Private developers and implementers have one year for health, education, justice, security, economy and finance, two years for transport, commerce and labour, three years for production, agriculture, energy and mining, and four years for everything else. Small enterprises with annual sales between 150 and 1,700 UIT have two years and microenterprises up to 150 UIT have three. Public bodies run separately: one year for the three branches of government and autonomous constitutional bodies, two for EsSalud, regional governments, public universities and state enterprises, three for Type A, B and C local governments.

Which authority enforces AI regulation in Peru, and what are the penalties?

Article 4 of Law No. 31814 designates the Presidency of the Council of Ministers, acting through the Secretariat of Government and Digital Transformation (SGTD), as the national technical and normative authority. Neither the Law nor the regulation creates an AI-specific fine. Enforcement runs by referral: Article 34.1 has the SGTD report non-compliant officials to the Contraloria General de la Republica, Article 34.2 refers suspected intellectual property, data protection or fundamental rights violations to the competent sanctioning authorities, and Article 36.2 lets affected persons complain to INDECOPI, the cybercrime division of the national police, or the national data protection authority.

Does Peru's data protection law apply to AI-driven decisions?

Yes, and this is where the fines are. Law No. 29733 is enforced by the Autoridad Nacional de Proteccion de Datos Personales of the Ministry of Justice and Human Rights, which Article 26.1 of the AI regulation names directly. Its implementing regulation was replaced by Decreto Supremo No. 016-2024-JUS, published 30 November 2024 and in force 120 calendar days later, repealing Decreto Supremo No. 003-2013-JUS. That regulation carries a full Title III on infractions and sanctions, with minor, serious and very serious grading fined under Article 39 of the Law and coercive fines capped at 100 UIT.

References

  1. Congress of the Republic of Peru. Ley No. 31814, Ley que promueve el uso de la Inteligencia Artificial en favor del desarrollo economico y social del pais. Approved in Lima 13 June 2023, promulgated 4 July 2023, published in El Peruano 5 July 2023. busquedas.elperuano.pe.
  2. Presidency of the Council of Ministers (Peru). Decreto Supremo No. 115-2025-PCM, approving the regulation of Ley No. 31814. Signed 8 September 2025, published in El Peruano 9 September 2025. Six titles, thirty six articles, six final complementary provisions; in force ninety business days after publication except the First, Second, Fourth and Fifth final complementary provisions. busquedas.elperuano.pe.
  3. Same regulation: Article 3 (scope, including the private sector), Article 4 (exclusions), Article 6(j) (definition of an AI system), Article 7 (principles), Article 8 (SGTD powers, including binding opinions and annual reporting to Congress), Article 22 (three risk categories), Article 23 (prohibited uses, and the Article 23.3 consultation route), Article 24 (high-risk uses, and the Article 24.2 consultation route), Article 25 (algorithmic transparency), Article 26 (data protection), Articles 28 to 30 (public-sector obligations), Articles 31 and 32 (private-sector obligations), Article 34 (referrals), Article 36 (complaints), and the First to Sixth final complementary provisions.
  4. Ley No. 29733, Ley de Proteccion de Datos Personales (Peru), and Decreto Supremo No. 016-2024-JUS approving its regulation, signed 29 November 2024 and published 30 November 2024 as a special supplement in El Peruano, in force 120 calendar days after publication and repealing Decreto Supremo No. 003-2013-JUS. Title III sets infractions and sanctions. gob.pe.
  5. Resolucion Ministerial No. 152-2026-PCM of 29 April 2026, published 1 May 2026, approving the Estrategia Nacional de Inteligencia Artificial 2026 to 2030, delivering on the Fourth Final Complementary Provision. Resolucion Ministerial No. 049-2026-PCM, published 15 February 2026, approving the Estrategia Nacional de Gobierno de Datos 2026 to 2030.
  6. Regulation (EU) 2024/1689 (EU AI Act), for comparison, including Article 26 (deployer obligations), Article 27 (fundamental rights impact assessment), Article 43 (conformity assessment) and Article 99 (penalties).
  7. NTP-ISO/IEC 42001:2025, made mandatory for Peruvian public entities developing AI systems by Article 28.2 of Decreto Supremo No. 115-2025-PCM, with NTP-ISO/IEC 27002 and NTP-ISO 31000 made obligatory by the Sixth Final Complementary Provision.