Colombia proposes an AI law modelled on the EU AI Act; commentary criticises insufficient adaptation to local conditions
The Colombian parliament is considering bill 025/2026, which copies the risk-based model of the EU AI Act. According to a commentary published by Tech Policy Press, the law does not account for the weaker institutional and economic capacity of the country and could burden domestic companies while leaving foreign AI developers unrestricted.
The Colombian House of Representatives is considering bill 025 of 2026, which aims to regulate the development and deployment of artificial intelligence systems. It was submitted to parliament by the parliamentary group of the Historic Pact party shortly before its departure from government. The proposal applies to developers, providers and operators of AI systems and, for systems that may significantly affect fundamental rights, establishes obligations such as risk and impact assessments, transparency, human oversight and monitoring, along with public oversight and penalties for non-compliance. The structure of the proposal, based on risk categories, follows the model of the EU AI Act regulation.
According to a commentary published by Tech Policy Press, the main problem is that the proposal adopts the architecture of European regulation without accounting for different institutional and economic conditions. According to the author, the EU AI Act regulation emerged in the context of a single market with hundreds of millions of people, established national authorities, expertise and financial resources that allow responsibility to be distributed among developers, providers, operators and regulators. Colombia can adopt European principles, but according to the author, it cannot simply import the institutional capacity that makes them enforceable.
The author highlights the risk of so-called regulatory transplantation: a sophisticated regulatory framework could create obligations that local companies and public institutions are unable to meet, while foreign companies developing the most powerful systems would remain effectively unrestricted. According to the article, the division of responsibility between system providers and operators is also problematic — a Colombian company may deploy a high-risk system developed abroad without access to its model, training data or internal documentation, meaning it could bear the greatest burden despite having no control over the technology. Who decides whether a system belongs in the high-risk category, and through what procedure, also remains an open question: article 5 of the proposal sets out general criteria but also allows the national AI authority to amend this list through a reasoned administrative act following a public consultation; under article 7, this authority is to be the Ministry of Science, Technology and Innovation. You can find details in the source article.
Why it matters
The text describes a general risk that may also arise in other countries considering AI regulation based on the European model: without adequate regulatory capacity, there is a risk that the law will mainly affect local companies and public institutions, while large foreign providers of AI systems remain effectively beyond the reach of enforcement. For companies operating in Colombia or planning to deploy AI systems developed elsewhere there, this means a risk that they would bear obligations for risk assessment, documentation and human oversight even for technologies whose internal workings they cannot access.
Two audiences, two different impacts
What this means
For individuals
If you develop or deploy AI systems in Colombia, it is worth following the progress of bill 025/2026 – in the future, it could introduce risk assessment and documentation obligations even for models developed by a third party to which you do not have full access.
For a business
Under the proposed bill, companies deploying AI systems in Colombia could face new obligations for risk assessment, transparency and human oversight, including for systems developed by foreign suppliers whose data and documentation they cannot access, while foreign developers themselves would, according to critics, remain outside the direct reach of regulation.
Risks and complianceCheck the original
Event sources
only one source so far · 1 publisher, 1 independent. We count feeds from the same owner only once.