HomeAI NewsColombia’s AI Law Faces Key Challenges

Colombia’s AI Law Faces Key Challenges

Date:

Related stories

Quickchat AI Review: Is It Worth the Price?

Quickchat AI is worth the price for small and...

Runway Gen-4 Review: Is It the Best AI Video Generator?

Runway has stood as the professional AI video platform...

Surfer SEO Review: Is It Worth the Price?

Surfer SEO built its name on one job: tell...

Adobe Firefly Review: Best AI Image Tool for Designers?

Adobe Firefly launched in public beta back in March...

Cursor AI Review: Is It the Best AI Code Editor?

Cursor is a code editor built as a fork...
spot_imgspot_img

Colombia is moving toward a new legal framework for artificial intelligence, but the country faces a difficult question before adopting a broad AI regulation: does it have the institutional, technical and economic capacity to enforce the rules effectively?

Bill 025 of 2026, currently before the Colombian House of Representatives, seeks to establish rules for the ethical and responsible development and use of artificial intelligence. The proposal would apply to developers, providers and deployers of AI systems and introduce obligations for systems considered capable of significantly affecting fundamental rights or other protected interests.

The proposal includes risk and impact assessments, transparency requirements, human oversight, monitoring, public supervision and sanctions for non compliance.

The objective is important. Artificial intelligence is already changing employment, education, public administration, security and access to services. Colombia therefore has strong reasons to establish safeguards around the technology.

However, creating an advanced legal framework is only one part of effective AI governance. The bigger challenge is ensuring that Colombia has the institutions, expertise, infrastructure and resources required to enforce those rules.

What Is Colombia’s AI Bill 025 of 2026?

Bill 025 of 2026 is designed to regulate artificial intelligence in Colombia and promote its ethical and responsible development.

The proposed framework follows a risk based approach. AI systems that could create significant risks to fundamental rights or other protected interests would face stronger requirements.

These requirements could include impact assessments, transparency measures, human oversight, monitoring and regulatory supervision.

The proposal also gives the national AI authority an important role in determining which AI applications should be considered high risk. Article 5 establishes general categories and criteria for risk classification, while allowing the national AI authority to update the list of high risk uses through a reasoned administrative act following public consultation.

Article 7 identifies the Ministry of Science, Technology and Innovation as the relevant authority and gives it the ability to issue binding technical recommendations concerning the risk level of AI systems.

Colombia Is Looking Toward the European Union AI Act

The structure of Colombia’s proposal has similarities with the European Union’s Artificial Intelligence Act.

The EU framework uses a risk based regulatory model and establishes different responsibilities for AI providers and deployers. It also introduces stronger requirements for high risk AI systems.

For Colombia, the European approach provides a useful reference point. However, adopting the principles of the EU AI Act is different from reproducing its regulatory structure without adapting it to local conditions.

The European Union operates within a large integrated market supported by national authorities, technical specialists, administrative institutions and significant financial resources.

Colombia operates under different economic and institutional conditions.

This difference matters because laws depend on the capacity of governments to monitor compliance, investigate violations and impose meaningful sanctions.

Why Regulatory Capacity Matters for AI Governance

AI regulation cannot work effectively through legislation alone.

Authorities need people with technical expertise who can understand AI systems, evaluate risk assessments, conduct investigations and determine whether companies are complying with their obligations.

They also need access to information, technological infrastructure, inspection mechanisms, adequate budgets and cooperation with regulators in other countries.

The proposed Colombian framework includes impact assessments, oversight mechanisms and institutional structures for AI governance. The central question is whether the institutions responsible for these tasks will have sufficient resources and technical capabilities to carry them out effectively.

Without that capacity, Colombia could create sophisticated legal requirements that exist largely on paper.

The Challenge of Regulating Foreign AI Companies

One of the biggest challenges for Colombia is that many of the most powerful AI systems are developed outside the country.

A Colombian business may use an AI model created by a foreign technology company. That local business may have control over how the system is deployed, but it may not have access to the model architecture, training data, evaluation procedures or internal safety mechanisms.

This creates an important regulatory problem.

How can a company be expected to fully explain, audit or assess a technology that it does not control?

A small Colombian company could face extensive compliance requirements while the foreign company responsible for developing the underlying model remains outside the country’s direct regulatory reach.

This could create an imbalance in which the organizations closest to the consequences of AI carry substantial regulatory responsibilities, while the organizations with the greatest technological power face fewer practical constraints.

Who Should Be Responsible for High Risk AI?

The question of responsibility becomes particularly important when AI systems are classified as high risk.

Under the European model, providers of high risk AI systems have responsibilities related to documentation, risk management and compliance. Deployers are responsible for how those systems are used, including human oversight and monitoring.

That distinction becomes more complicated in Colombia.

Consider a local company that deploys a high risk AI system developed by an overseas provider. The Colombian company may be able to control the way the technology is used, but it may have no access to the underlying model or the information needed to conduct a complete assessment.

Applying identical obligations without considering who actually controls the technology could place excessive responsibility on local companies.

A more effective system would consider both the risk created by an AI system and the level of technological control held by each participant in the AI supply chain.

Who Decides Whether an AI System Is High Risk?

The classification of AI systems as high risk is not simply a technical matter.

A high risk classification can determine which legal obligations apply to a company and what uses of an AI system may be restricted.

For that reason, the process needs clear criteria, transparency and meaningful opportunities for review.

The Colombian proposal gives the national AI authority significant responsibilities in determining and updating high risk applications. The Ministry of Science, Technology and Innovation would play a central role in this process.

Technical expertise is necessary, but decisions that could affect fundamental rights should also remain subject to clear legal standards and effective oversight.

The broader issue is algorithmic due process.

If an AI system can influence decisions affecting people’s rights, individuals and organizations should have meaningful ways to understand, challenge and review those decisions.

The Colombian AI Regulation Paradox

Colombia faces a broader technological problem that goes beyond the proposed legislation.

The country increasingly uses AI systems, digital infrastructure and technological platforms developed by companies based outside Colombia.

This means Colombia can regulate how those technologies are used without necessarily controlling the underlying infrastructure.

The problem is especially significant for smaller businesses.

A local company could deploy an AI model developed abroad without having access to its training data, architecture or internal evaluation systems. The company can decide how it uses the technology, but it cannot fully govern the technology itself.

This creates a major asymmetry between technological users and technological developers.

Countries in the Global South increasingly depend on digital infrastructure created by companies concentrated in a relatively small number of countries.

That dependence raises questions about technological sovereignty, data and access to computing infrastructure.

AI governance therefore cannot focus only on how companies use AI. It should also consider who controls the models, infrastructure, computing resources and technical knowledge behind the technology.

Colombia Should Regulate AI Based on Its Own Capacity

The answer is not to avoid AI regulation.

Colombia needs rules that protect fundamental rights and reduce the risks created by artificial intelligence.

However, the regulatory framework should be proportional to the actual risks and compatible with the country’s institutional capacity.

The strongest safeguards could initially focus on sectors where AI could cause particularly serious harm.

These include healthcare, justice, security, surveillance and public services.

Different levels of risk should lead to different regulatory requirements. The responsibilities of each organization should also reflect how much control that organization actually has over the technology.

AI Regulation Should Focus on High Impact Areas

Not every AI application presents the same level of risk.

An AI system used for a low impact administrative task should not necessarily face the same compliance requirements as an AI system used in healthcare, criminal justice, public security or government services.

A proportional framework could allow Colombia to concentrate its regulatory resources on applications where mistakes or misuse could have serious consequences for people’s rights and safety.

This would also reduce unnecessary burdens on smaller companies and organizations that use AI tools without having control over the underlying technology.

Colombia Should Not Simply Copy the EU AI Act

The European Union AI Act provides useful lessons for Colombia, particularly its risk based approach and distinction between providers and deployers.

However, Colombia should adapt those principles rather than simply reproduce the European framework.

The country’s regulatory system needs to reflect its own institutional capacity, technology ecosystem and economic conditions.

The central objective should be effective AI governance rather than regulatory similarity with Europe.

A law that looks sophisticated but cannot be effectively enforced would provide limited protection.

A more practical framework would establish clear responsibilities, prioritize high risk applications, strengthen regulatory expertise and consider the difference between companies that develop AI systems and companies that merely deploy them.

What Colombia Needs for Effective AI Governance

Effective AI regulation will require more than a new law.

Colombia needs qualified officials who understand artificial intelligence and related technologies.

It also needs effective inspection and investigation mechanisms, appropriate sanctions, access to technical information and cooperation with foreign regulators.

The country may also need to strengthen its own technological capabilities so that it is not entirely dependent on foreign AI infrastructure.

Building domestic expertise and technological capacity would make it easier for Colombian institutions to evaluate the systems they are expected to regulate.

The Bigger Question Behind Colombia’s AI Law

The debate surrounding Bill 025 of 2026 is ultimately about more than artificial intelligence regulation.

It is about technological power.

Who develops the most powerful AI systems?

Who controls the infrastructure on which they operate?

Who owns the computing resources?

Who has access to the technical knowledge needed to evaluate these systems?

And who has the authority and capacity to impose meaningful limits?

These questions are increasingly important as AI becomes embedded in economic activity, government services and everyday life.

Colombia therefore needs an AI regulatory framework that protects people without creating unrealistic obligations for organizations that lack control over the technology they use.

Conclusion

Colombia has a legitimate reason to regulate artificial intelligence. AI is already influencing employment, education, government, security and fundamental rights, making responsible governance increasingly important.

Bill 025 of 2026 provides an opportunity to establish stronger safeguards and introduce a risk based approach to AI regulation.

But Colombia should avoid treating the European Union AI Act as a model that can simply be copied.

The country should learn from Europe’s experience while adapting the rules to Colombian institutions, businesses and technological realities.

The most effective AI regulation would focus on high risk applications, establish clear responsibilities between providers and deployers, consider the actual level of technological control held by each actor and strengthen the capacity of Colombian regulators.

The future of AI governance will not depend only on what artificial intelligence systems are allowed to do.

It will also depend on who has the power to build those systems, who controls the infrastructure behind them and who has the real ability to regulate them.

That is the central question Colombia should answer as it develops its AI law.

Latest stories

spot_img