Skip to main content
v2026.11,858 entries · CC-BY 4.0

Kazakhstan’s AI Law No. 230-VIII: What It Actually Requires

On 17 November 2025, President Kassym-Jomart Tokayev signed Law of the Republic of Kazakhstan No. 230-VIII On Artificial Intelligence. It entered into force on 18 January 2026, runs to seven chapters and 28 articles, and is the first dedicated, standalone AI statute adopted by a Central Asian state. Uzbekistan followed within days, but took a […]

Written and maintained by CASRAI Editorial Board

Last updated

On 17 November 2025, President Kassym-Jomart Tokayev signed Law of the Republic of Kazakhstan No. 230-VIII On Artificial Intelligence. It entered into force on 18 January 2026, runs to seven chapters and 28 articles, and is the first dedicated, standalone AI statute adopted by a Central Asian state. Uzbekistan followed within days, but took a different route: the act President Mirziyoyev signed on 21 January 2026 amends existing information and administrative legislation rather than creating a freestanding AI law.

Kazakhstan’s law borrows the vocabulary of the European AI Act family — risk tiers, prohibited practices, synthetic-content labelling — and a fast reading makes it look like a copy. It is not. Three structural choices set it apart: risk tiers are defined by severity of consequence rather than by a fixed annex of use cases; the route to “trusted” status for high-risk systems runs through private auditors working to Kazakhstan’s existing information-systems audit rules rather than through anything resembling a notified body; and the same ministry that regulates AI also operates a national platform that allocates state compute to economic sectors it designates as priorities. That last mechanism has no counterpart in the statutes this reference already covers.

Who administers it

The authorised state body is the Ministry of Artificial Intelligence and Digital Development, created in September 2025 — a single ministry holding strategic, regulatory, implementation and supervisory functions together. This is a meaningful contrast with the EU’s distributed model of national market-surveillance authorities plus a central AI Office, and with the sector-regulator approach the United Kingdom has favoured. In Kazakhstan, the body that writes the classification criteria, approves documentation requirements, designates which sectors receive subsidised compute, and supervises compliance is the same body.

Two classification axes, not one

Most coverage of the law reports the three risk tiers and stops. The statute actually classifies AI systems along two axes, and the second one is easy to miss.

Risk, defined by what happens when it fails

The tiers are framed around the consequence of malfunction, not around a listed use case:

  • Minimum risk — disruption has minimal impact on users.
  • Medium risk — failure may cause material damage or moral harm, or reduce operational efficiency.
  • High risk — disruption may lead to emergencies, or to threats to defence, security, the economy, critical infrastructure, or the lives of citizens.

The difference from the EU AI Act is architectural rather than cosmetic. The AI Act fixes high-risk status largely by enumeration: a system lands in the category because it appears in Annex III or functions as a safety component of a regulated product. Kazakhstan instead asks a consequence question, which makes classification a judgement the operator must make and document about its own deployment context. The same software can sit in different tiers depending on where it is used. That flexibility cuts both ways — it adapts to novel applications an annex would miss, and it leaves more room for an operator to argue its way downward.

Autonomy, as a separate dimension

Alongside risk, systems are graded by autonomy:

  • Low — a human makes all final decisions.
  • Medium — the system decides autonomously, but a human can correct or cancel the decision.
  • High — human correction is excluded or technically impossible.

Separating autonomy from risk is a more sophisticated move than it first appears, and it is one of the few places where a national statute has put an agentic-behaviour dimension directly into binding text. A low-risk, high-autonomy system and a high-risk, low-autonomy system present genuinely different governance problems, and a single tier label collapses that distinction. Reporting on the law also indicates that restrictions attach to systems whose autonomous decision-making could cause harm without a correction path.

Prohibited practices

Here the law does track the AI Act family closely. Prohibited are systems that:

  • use subliminal, manipulative or other techniques that distort a person’s behaviour or limit independent decision-making;
  • exploit vulnerabilities arising from age or disability in a way that causes harm;
  • perform social scoring — assessing individuals or groups by behaviour or personal characteristics — outside legally permitted cases;
  • determine a person’s emotions without consent, outside legal exceptions;
  • classify people on the basis of biometric or sensitive characteristics for discriminatory purposes;
  • process personal data unlawfully.

The list is familiar. What is different is the institutional setting around it: these prohibitions sit in a short statute supervised by one ministry, not in a 100-plus-article regulation with a dedicated enforcement architecture and staged application dates.

“Trusted” status runs through private auditors — and it is voluntary

This is the provision most worth understanding, and the one most often described inaccurately.

High-risk systems may be entered on lists of trusted AI systems maintained by sector agencies and published on government websites. To get listed, the owner applies with evidence of intellectual-property rights and a positive audit conclusion. The audit examines the quality and lawfulness of training data and the absence of prohibited capabilities. Agencies review applications within a reported ten working days.

Two features make this a genuinely different conformity architecture:

The auditor is a private information-systems auditor, not a purpose-built AI conformity body. The audit is conducted under Kazakhstan’s pre-existing rules for auditing information systems — the framework traced to Ministry of Information and Communications Order No. 263 of 13 June 2018. Kazakhstan did not build a new accreditation regime for AI assessors; it pointed at the IT-audit profession it already had. That is fast and cheap to stand up, and it sidesteps the bottleneck that notified-body capacity has become in the EU. The trade-off is that information-systems audit standards were written to test controls, integrity and availability — not to evaluate model behaviour, training-data provenance at scale, or emergent capability. Whether that profession can answer the questions the statute asks of it is an open question, and one this reference watches closely in its work on third-party evaluator standards and methodology.

Listing appears to be optional, not a precondition for market access. Multiple analyses describe participation in the trusted lists as voluntary rather than mandatory. If that reading is right, it is the single largest divergence from the EU model: the AI Act makes conformity assessment a gate you must pass before a high-risk system is placed on the market, whereas Kazakhstan’s trusted list functions more like a quality signal or a procurement credential. The binding obligations on high-risk operators — risk management across the lifecycle, safety and reliability, protection against unauthorised access, documentation, user support — apply regardless of whether the owner ever seeks listing.

State-directed compute allocation

The law gives formal legal status to a National AI Platform, operated by National Information Technologies JSC, as a controlled environment for developing, training and trial-operating AI models. It also creates channels for designated priority sectors to access state computing power and curated data.

The compute behind it is real. Kazakhstan’s national supercomputing cluster, Alem.cloud, is built on 64 HGX servers with 512 NVIDIA H200 GPUs, rated at up to 2 exaflops at FP8, and has been placed 86th on the TOP500 list — the most powerful cluster in Central Asia. Reported priority areas for capacity include education, healthcare, agriculture, water supply, public administration, oil and gas, mining and metallurgy, energy, geological exploration, transport and logistics, industry, construction and robotics.

The governance point is the allocation power, not the hardware. The authorised body determines which sectors of the economy get access to national computing resources. Set that against the compute-governance model this reference describes elsewhere: export controls and FLOP thresholds that restrict who may obtain or train above a certain scale operate as a ceiling — they are instruments of restriction. Kazakhstan’s mechanism is a floor, and a directive one: the state holds compute and decides which parts of the economy receive it. Both are compute governance. They point in opposite directions, and a jurisdiction can run both at once. For a country that is not a chip producer, allocation may simply be the more available lever.

There is a narrow but real research-administration angle here. Alem.cloud capacity is described as available to government agencies, research institutes, universities, businesses and startups, and education sits among the listed priority areas. For a researcher in Kazakhstan, access to significant compute is therefore mediated by a ministry’s sector-priority determination rather than by a competitive grant or an institutional cluster allocation. That is a different research-computing procurement path from the one most sponsored-programmes offices are built around, and worth noting for anyone administering collaborations with Kazakh institutions. The statute itself is not a research-administration instrument, and nothing in it speaks to human-subjects review or export-control obligations.

Synthetic content must be labelled twice over

Distribution of synthetic results — deepfakes and generated content — is permitted only where the output is labelled in machine-readable form and the user receives a clear visual warning. Both are required; one does not substitute for the other.

The dual requirement is worth dwelling on, because disclosure regimes usually pick a side. Machine-readable provenance metadata serves platforms, downstream classifiers and forensic review, and survives at scale — but it is invisible to the person actually looking at the content, and is routinely stripped by re-encoding and re-upload. A visible warning serves the viewer directly but does not travel and cannot be checked automatically. Requiring both is more demanding than most of what is in force elsewhere, and it addresses the failure mode where a technically compliant file reaches an audience with no perceptible indication of what it is. Owners and holders bear the disclosure responsibility, and AI products used in mass media are subject to mandatory disclosure.

Training data: a third path on copyright

The training-data and copyright provisions are the part of this statute most likely to matter outside Kazakhstan, because they describe a settlement that neither of the two dominant approaches has produced.

  • Data libraries. The law defines data libraries as a category, created by private entities or by the authorised body, and capable of being hosted on the national platform. Creator information must be held in machine-readable form, and data is provided for pre-defined and legitimate purposes.
  • Opt-out by default. Use of copyrighted works for AI training is permitted unless the rightsholder has expressed a prohibition in machine-readable form. Where no such prohibition exists, training use is not treated as an infringement of exclusive rights. Where it does exist, the free-use exceptions for education and science do not rescue the training use.
  • Training is not a licence to publish. Permission to train does not grant rights to reproduce, adapt, publicly display, perform or distribute the underlying works.
  • Human authorship required for output. AI-assisted output attracts copyright only where there is creative human input.
  • Prompts can themselves be protected. A prompt that reflects genuine intellectual or creative effort is recognised as an object of copyright in its own right.

Put beside the EU’s text-and-data-mining exception with its reservation mechanism, and beside the United States, where the question is being settled case by case through fair-use litigation, Kazakhstan’s combination is distinctive in one respect: it pairs the opt-out with a state-operated platform that can host the data libraries and hold the machine-readable creator information. The opt-out register and the training infrastructure sit inside the same national system. That is an administrative answer to the practical objection that dogs every opt-out regime — that a reservation nobody can reliably discover is not a reservation at all. Whether it works depends entirely on implementing regulations that were not public at the time of writing.

The protectable-prompt provision is a genuine novelty. It is also narrow: recognising a creative prompt as a copyrightable work says nothing about who owns the output generated from it.

Penalties: resolving an apparent contradiction in the reporting

Secondary coverage of the penalty scale looks contradictory. One widely cited summary presents a range of roughly USD 127.50 to USD 1,700 banded by entity size; another gives 15 to 200 monthly calculation indices (MCI, the Kazakh MRP) with suspension available; a third gives 15 to 100 MCI. These are not competing accounts. They are the same figures expressed in different units, and one of them quotes first-offence amounts only.

The penalties were introduced by a companion act, Law No. 232-VIII, amending the Code of Administrative Offences, and are reported to sit at Article 641-1. The MCI for 2026 is 4,325 tenge. Converting the MCI figures at the exchange rate implied by the published dollar amounts — about 509 tenge to the dollar — reconciles every band exactly:

Entity First offence Repeat within 12 months
Individuals 15 MCI (≈ USD 128) 30 MCI (≈ USD 255)
Small entities and non-profits 20 MCI (≈ USD 170) 50 MCI (≈ USD 425)
Medium enterprises 30 MCI (≈ USD 255) 70 MCI (≈ USD 595)
Large enterprises 100 MCI (≈ USD 850) 200 MCI (≈ USD 1,700)

So the full statutory range is 15 to 200 MCI; the 15-to-100 figure is the first-offence range; and the dollar figures are the same ladder priced in currency. Two offence types are reported: failing to inform users that output is synthetic in a manner likely to mislead, and failure by a high-risk system owner or operator to carry out risk management where this produces negative consequences — harm to health, dissemination of prohibited information, discrimination, or infringement of rights. Suspension or prohibition of the AI system’s operation is available as an additional measure.

The monetary amounts are small. A large enterprise facing a maximum repeat fine of roughly USD 1,700 is not being deterred by the fine. If this regime bites, it will bite through suspension of the system and through exclusion from the trusted lists and the state compute that the same ministry controls — not through the penalty schedule. That pattern is familiar from Japan’s AI promotion statute, which carries no penalties at all, and it is a reminder that the enforcement question is rarely answered by reading the fine column.

Mandatory liability insurance — a real first

During the law’s passage the Senate added a requirement that liability for damage caused by AI systems be insured, replacing what had been a voluntary arrangement. The statute frames this as insurance carried out in accordance with the laws of Kazakhstan, which means the operative terms — who must carry it, at what limits, against which risks — depend on implementing legislation rather than on the AI law itself. The law also shifts owners toward prevention, obliging them to take measures in advance to avoid harm rather than only to answer for it afterwards.

This is worth flagging for readers of our analysis of why no U.S. state requires AI liability insurance. That finding is specific to American states and remains accurate; Kazakhstan does not contradict it. But it does show that the mandate is no longer hypothetical anywhere in the world, and it supplies the first live test of a question the U.S. debate has only modelled: whether an insurance market can price AI liability when a statute compels the purchase before the actuarial basis exists. Until the implementing rules appear, the requirement is a commitment rather than an operating regime.

What the law does not say

Two cautions, because this is where confident summaries tend to overreach.

Extraterritorial reach is not established. None of the available analyses identifies a provision extending the law to foreign providers serving Kazakh users from abroad, in the way the EU AI Act reaches providers placing systems on the Union market. Some secondary coverage describes the law loosely as applying to organisations whose AI “touches Kazakhstan,” but that is a characterisation, not a citation to a scope article. Anyone assessing exposure for a non-resident provider should treat the question as open and get an opinion on the Kazakh-language text rather than relying on any English summary, including this one.

Dates are misreported in circulation. At least one published analysis renders the entry into force as 18 January 2025, a year early. The law was signed on 17 November 2025 and entered into force on 18 January 2026. One tracker gives 17 January 2026 for the administrative-offence amendments, a day before the parent statute; we have not been able to confirm that one-day difference against the official text, and note it rather than assert it.

We were not able to retrieve the consolidated official text from Kazakhstan’s Adilet legal information system, which serves its documents through an interface that does not expose them to retrieval. Every provision above therefore rests on professional analyses of the statute rather than on the statute itself, and article-level citations should be verified against the original before being relied on.

How it fits the broader pattern

Kazakhstan’s statute belongs to a now-recognisable category: a mid-sized jurisdiction adopting AI-Act vocabulary while building a materially lighter institutional apparatus underneath it. Korea’s AI Basic Act and Italy’s Law 132/2025 each do a version of this. The vocabulary converges; the enforcement architecture does not. Anyone building a compliance programme across jurisdictions should expect the defined terms to look reassuringly similar and the obligations they trigger to differ substantially — which is precisely why our jurisdiction map of AI regulation worldwide tracks mechanisms rather than terminology.

The specific contribution Kazakhstan makes to that map is the pairing of a light regulatory touch with a heavy industrial one. The regulatory obligations are modest and the fines are nominal, but the state operates the compute, curates the data libraries, hosts the opt-out infrastructure, and decides which sectors get served first. The leverage is not in the penalty schedule. It is in the allocation.

A note on vocabulary

Kazakhstan’s three-tier scheme grades net expected harm from a system’s failure, which is a different object from the capability-based thresholds used in frontier-lab safety frameworks. In NIKOLAI, CASRAI’s independent AI-safety dictionary, that distinction is carried by the Risk Level element in track N4, defined as the overall graded risk assigned to a model, domain or activity as a whole, as distinct from capability thresholds describing capabilities rather than net risk after mitigations. Kazakhstan’s tiers read as a risk-level construct, not a capability-threshold construct.

NIKOLAI is CASRAI’s own dictionary and is not endorsed by any lab, evaluator or regulator. Its crosswalk rows are shadow mappings — CASRAI’s readings of published documents — unless an organisation has filed a Mapping Declaration. No mapping has been filed for Kazakhstan’s statute, and the observation above is an editorial reading offered for orientation, not an official alignment.

Sources

This guide draws on the EY Kazakhstan tax alert on the adoption of the law; the U.S. Library of Congress Global Legal Monitor entry of 12 January 2026; Kinstellar’s review of Kazakhstan’s digitalisation and AI regulations; AIPPI’s note on Kazakhstan’s first AI law; the Legal500 legal-development notice on Law No. 230-VIII; Mondaq analyses of the law and of the Ministry of Artificial Intelligence; and the Regulations.AI record for Law No. 232-VIII amending the Code of Administrative Offences. Infrastructure figures for Alem.cloud come from Kazakhstan’s Prime Minister’s official information source. Figures and dates were cross-checked across sources and, where they could not be reconciled, are flagged above.

Follow CASRAI

Research-administration guidance, standards updates and independent tool reviews.

Ask CASRAI · free to try

Ask about Kazakhstan’s AI Law No. 230-VIII: What It Actually Requires

Ask your first 2 questions free below. Subscribers get 150 a day for $29 a month.

An AI assistant specialized in research administration. It cites the sources behind every answer, labels web answers and says when it can't answer.

Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.

Works on this site and inside Claude, Cursor and the AI tools you already use.

Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →

Ask CASRAI · Regulatory Radar

AI policy question? Get an answer citing the framework.

An AI assistant specialized in research administration. Every answer links its sources to check before you act. 2 questions free, no account. $29/month after.

  • Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.
  • Every answer numbers its sources and links each one, so you can check the source yourself.