Written and maintained by CASRAI Editorial Board
Last updated
Short answer: Yes, Peru has an enacted national AI law — Ley N° 31814, “Ley que promueve el uso de la Inteligencia Artificial en favor del desarrollo económico y social del país,” passed by Peru’s Congress and published in El Peruano on 5 July 2023. It is widely credited, correctly, as the first country in Latin America to enact dedicated AI legislation — ahead of Brazil’s PL 2338/2023, which the Senate approved the same year but which is still awaiting a Chamber opinion, and well ahead of Mexico, Argentina, Chile and Colombia, none of which has enacted a comparable law. But the statute itself is a short, declarative, promotion-oriented text: principles, a designated authority, no risk tiers, no obligations, no penalties. Two years later, on 9 September 2025, Peru’s executive branch published the law’s implementing regulation — Decreto Supremo N° 115-2025-PCM — and that decree is where an EU-AI-Act-shaped risk taxonomy actually shows up: prohibited uses, high-risk categories, and real obligations attached to them. What still is not there, in either document, is an AI-specific penalty regime. This guide separates what the 2023 law does from what the 2025 decree added, because most secondary coverage conflates the two.
What Congress Actually Passed in 2023
Ley 31814’s Article 1 states its purpose: to promote AI adoption within Peru’s national digital-transformation process, “privilegiando a la persona y el respeto de los derechos humanos” (centring the person and respect for human rights). Its preliminary title sets out principles — risk-based safety, ethics, transparency, privacy, multi-stakeholder participation, alignment with internet-governance norms — but these are stated as orientations, not as operative rules with thresholds attached. Article 4 designates the Presidencia del Consejo de Ministros’ Secretaría de Gobierno y Transformación Digital (SGTD) as the ente rector — the governing technical-normative authority for AI policy. That is an existing digital-government secretariat given a new mandate, not a newly created multi-stakeholder council; readers who assume the law stood up a dedicated AI commission are assuming something the text does not contain.
Critically, the law does not itself classify AI systems by risk, does not itself impose obligations on developers or deployers, and does not itself create penalties. It is, in its own framing, promotional rather than restrictive: it authorises and directs the executive branch to build out the substantive rules later, through a reglamento. For two years, that reglamento did not exist, and analysts tracking Peru’s “AI regulatory boom” noted that a law whose rulebook is perpetually pending risks being, in practice, little more than a declaration of national interest.
The Decree That Actually Did the Work: D.S. N° 115-2025-PCM
That changed on 9 September 2025, when Peru published the reglamento of Ley 31814 as Decreto Supremo N° 115-2025-PCM — six titles, 36 articles. Its general provisions took effect roughly 90 business days later, in mid-January 2026, with staggered compliance deadlines of one to four years from September 2025 depending on sector and organisation size. This is the document that actually resembles an EU-AI-Act-style regime, and it is the document most “Peru has an AI law” summaries never reach.
Article 22 sorts AI systems into three tiers, and Article 23 lists what is banned outright: behavioural manipulation through subliminal or deceptive techniques; autonomous lethal decision-making without human oversight in civilian contexts; mass surveillance without legal basis; inference of sensitive traits from biometric data; real-time biometric identification in public spaces (with narrow exceptions for identity verification and serious-crime investigation); and crime prediction based on individual profiling. Article 24 lists eight high-risk categories — critical infrastructure, employment decisions, consumer credit, healthcare access and diagnosis, assessment of minors in education, access to social programmes, workplace emotion inference, and an open clause for uses with a high probability of stigmatisation or discrimination. Everything else falls into the general, “acceptable-risk” tier under Article 22.2, subject to the law’s principles but no enhanced burden.
| Tier | Article | What it covers |
|---|---|---|
| Prohibited | Art. 23 | Six banned uses: behavioural manipulation, unsupervised autonomous lethal systems, unlawful mass surveillance, sensitive-trait inference from biometrics, real-time public biometric ID, profiling-based crime prediction |
| High-risk | Art. 24 | Eight categories: critical infrastructure, employment, consumer credit, healthcare, education of minors, social-programme access, workplace emotion inference, plus an open discrimination-risk clause |
| Acceptable-risk | Art. 22.2 | Everything else — general principles apply, no enhanced obligations |
High-risk systems carry concrete duties under Articles 31–33: a registry documenting the system’s design principles, data sources and expected social and ethical impact; security protocols covering privacy, transparency, explainability and accountability, referencing standards including Peru’s own NTP-ISO/IEC 42001:2025; internal staff training on AI risk; effective human oversight in health, education, justice, finance and basic services, meaning personnel with actual authority to halt, correct or override the system; and a high-risk impact assessment that is voluntary but SGTD-incentivised, with findings retained for at least three years. Article 25 adds a transparency duty — telling users, clearly and in advance, that they are interacting with an AI system, and explaining rights-affecting decisions in accessible language. Article 26 ties personal-data handling throughout the AI lifecycle back to Peru’s existing data-protection law, Ley N° 29733.
What Still Is Not There: No AI-Specific Penalty Regime
This is the point where Peru’s framework genuinely stops resembling the EU AI Act, and it is worth stating precisely rather than rounding it to “no enforcement.” Articles 34–36 give SGTD a monitoring and supervisory role — it can identify apparent violations — but the decree does not hand SGTD, or any other body, a dedicated AI sanctions power or a schedule of AI-specific fines. Instead, SGTD refers violations onward to whichever existing regulator already has jurisdiction over the underlying harm: Peru’s data-protection authority (ANPDP, under the Ministry of Justice) for personal-data breaches, INDECOPI for consumer-protection and unfair-competition issues, the police’s DIVINDAT unit for computer-crime conduct, and the Comptroller General for public-sector violations. Citizens can also file complaints through a unified digital channel (gob.pe/iaperu).
In other words: Peru’s AI risk taxonomy is real, but its enforcement is entirely borrowed from pre-existing regimes that were not written with AI in mind. There is no dedicated AI regulator with independent sanctioning power, no AI-specific fine schedule, no mandatory pre-market conformity assessment or certification, and no independent third-party audit requirement — the high-risk impact assessment is SGTD-incentivised, not compulsory, and self-administered rather than externally verified. That is the accurate contrast with the EU AI Act: the risk taxonomy converges: the compliance infrastructure behind it does not.
Atomic Facts
| Fact | Detail |
|---|---|
| Law | Ley N° 31814, “Ley que promueve el uso de la Inteligencia Artificial en favor del desarrollo económico y social del país” |
| Enacted / published | 5 July 2023, El Peruano |
| Governing authority | SGTD (Secretaría de Gobierno y Transformación Digital), under the PCM — an existing secretariat, not a new council |
| Implementing regulation | Decreto Supremo N° 115-2025-PCM, published 9 September 2025; six titles, 36 articles |
| Regulation’s general effective date | ~mid-January 2026 (90 business days after publication); sector-specific compliance windows run 1–4 years from September 2025 |
| Risk tiers | Prohibited (Art. 23), High-risk (Art. 24), Acceptable-risk (Art. 22.2) |
| AI-specific penalties | None. Enforcement is referred to existing data-protection, consumer-protection, cybercrime and public-sector oversight regimes |
| First in Latin America? | Widely credited as the first enacted national AI law in the region; Peru also has a narrower 2024 law, Ley 32082, on AI in consular services |
Promotion, Not Restrict-and-Comply — and Why That Label Still Mostly Holds
CASRAI’s coverage of this cluster generally sorts jurisdictions into two postures: a restrict-and-comply model, where the state sets binding thresholds and enforces them directly (the EU AI Act’s high-risk compliance regime, China’s algorithm-registration and licensing approach), and a promotion-first model, where the state’s primary stated goal is adoption and the compliance layer, if any, is thinner or borrowed (Japan’s AI Promotion Act, which has no penalty clause at all). Peru is a genuine hybrid, and that is exactly why it is easy to describe wrong in either direction. Describe only the 2023 law and you get Japan’s picture — declarative, toothless, promotional. Describe only the 2025 decree’s risk tiers and you get something that sounds like the EU AI Act. Neither description alone is accurate; the law is promotional, and the decree it authorised built real risk categories without building real AI-specific enforcement to match. South Korea’s AI Basic Act, by contrast, took effect in January 2026 with its own dedicated administrative-fine structure — a useful marker of what Peru’s framework still lacks.
The regional point is the sharper one. “Peru has an AI law” is not an overstatement the way “Brazil has an AI law” currently is — Brazil’s PL 2338/2023 has not passed its second chamber. Mexico, Argentina, Chile and Colombia have soft-law guidance, ethical frameworks and policy declarations, not enacted AI statutes. Peru is the real exception in the region, and it earned that distinction twice over — once by enacting Ley 31814 in 2023, and again by actually publishing its reglamento in 2025 rather than leaving the law’s principles permanently undefined. For where this sits against the rest of the world, see CASRAI’s jurisdiction map of AI regulation and the ten-jurisdiction comparison of frontier AI law, neither of which currently carries a Peru row.
What This Means for Research Administration
Two mistakes are equally live here for a research office with Peruvian partners, vendors or subsidiaries. The first is assuming Peru has no binding AI rules at all and treating any Peru-facing AI use — an admissions-scoring tool, a grant-triage model, a health-research recruitment system — as unregulated; several of the Article 24 high-risk categories (education assessment of minors, healthcare access and screening, social-programme targeting) sit squarely inside common research-administration and hospital-adjacent AI use cases, and those trigger the registry, human-oversight and transparency duties described above once the sector’s compliance window opens. The second, opposite mistake is assuming Peru’s regime carries EU-AI-Act-level enforcement risk — audit exposure, AI-specific fines, a dedicated regulator to negotiate with — when in fact any consequence for non-compliance currently runs through Peru’s existing data-protection, consumer-protection or criminal-law channels, not a new AI-specific sanctions track. The defensible posture is to map Peru-facing AI use against Articles 22–26 on their own terms, not against either extreme.
Where NIKOLAI Fits
NIKOLAI is CASRAI’s own independent, unendorsed reference dictionary of frontier-AI-safety elements, live at casrai.org/nikolai. The comparison this guide draws — Peru’s Article 22–24 risk tiers against the EU AI Act’s risk pyramid — is exactly the kind of cross-regime comparison NIKOLAI’s Mapping Declaration element exists to keep honest. NIKOLAI defines a Mapping Declaration as “a statement by a party that one of its own documents or terms satisfies, corresponds to, or deliberately differs from a term or obligation in another regime” — a declaration by the mapped party itself, which is a different and stronger thing than an outside analyst’s reading. No Peruvian authority has filed a Mapping Declaration with NIKOLAI stating that D.S. 115-2025-PCM’s risk tiers correspond to the EU AI Act’s. The comparison drawn in this guide is therefore CASRAI’s own shadow mapping — a useful analytical parallel, not an official or endorsed equivalence, and NIKOLAI makes no claim of affiliation with Peru’s government or its AI framework. More on how NIKOLAI’s mapping system works is in NIKOLAI’s Mapping Declarations guide and the overview of NIKOLAI’s ten tracks.
Frequently Asked Questions
Does Peru have an enacted AI law?
Yes. Ley N° 31814 was passed by Peru’s Congress and published in El Peruano on 5 July 2023. It is widely credited as the first enacted national AI law in Latin America.
Is Ley 31814 comparable to the EU AI Act?
Not by itself. The 2023 law is a short, principles-based, promotional statute with no risk tiers, no obligations and no penalties. The risk taxonomy that resembles the EU AI Act — prohibited uses, high-risk categories, obligations attached to them — was added two years later, by the implementing regulation, not by the law Congress passed.
What is Decreto Supremo N° 115-2025-PCM?
It is Ley 31814’s implementing regulation (reglamento), published 9 September 2025: six titles and 36 articles that classify AI systems into prohibited, high-risk and acceptable-risk tiers and attach concrete obligations — a registry, security protocols, staff training, human oversight and an incentivised impact assessment — to high-risk systems. Its general provisions took effect around mid-January 2026, with sector-specific compliance windows running one to four years from September 2025.
Are there penalties for violating Peru’s AI rules?
Not AI-specific ones. The regulation gives SGTD a monitoring and referral role, not independent sanctioning power. Violations are referred to Peru’s existing data-protection, consumer-protection, cybercrime and public-sector oversight regimes, which enforce under their own pre-existing rules — not under any AI-specific fine schedule.
Does Ley 31814 create a national AI council?
No. It designates the Secretaría de Gobierno y Transformación Digital (SGTD), an existing digital-government secretariat under the Presidencia del Consejo de Ministros, as the governing authority. No new multi-stakeholder council or commission is created by the law or its regulation.
Do Mexico, Argentina, Chile or Colombia have comparable AI laws?
No. As of this guide’s research, none of the four has enacted a dedicated national AI statute; their frameworks consist of soft-law guidance, ethical principles and policy declarations. Brazil’s PL 2338/2023 was approved by the Senate but remains stalled in the Chamber of Deputies, unenacted. Peru is the regional exception.
Related Reading
- California’s CPPA ADMT Regulations: A Separate Regime From FEHA’s ADS Rules
- Italy’s D.Lgs. 160/2026: Police AI, Biometrics and AI Liability
- Vietnam’s Law on Artificial Intelligence No. 134/2025/QH15
- Kazakhstan’s AI Law No. 230-VIII: What It Actually Requires
- Latin America AI Regulation: Peru, Mexico, Argentina, Chile and Colombia Compared
- Brazil’s PL 2338/2023: Approved by the Senate, Stalled in the Chamber
- Korea’s AI Basic Act: What Took Effect in January 2026
- Japan’s AI Law Has No Penalties — and Got Its First Live Test
- China’s AI Regulation, Explained
- EU AI Act High-Risk Compliance Checklist
- AI Regulations Around the World: A Jurisdiction Map
- Frontier AI Law: 10 Jurisdictions Compared
- NIKOLAI’s Mapping Declarations, Explained
- What Is NIKOLAI? CASRAI’s Frontier-AI-Safety Dictionary Explained
Sources
- Congreso de la República del Perú, Ley N° 31814, published in El Peruano, 5 July 2023: title, enactment date, and Article 1 purpose language.
- Presidencia del Consejo de Ministros, Decreto Supremo N° 115-2025-PCM (Reglamento de la Ley N° 31814), published in El Peruano, 9 September 2025: structure (six titles, 36 articles), Articles 22–26 risk-tier definitions and obligations, Articles 31–36 supervision and referral provisions.
- International Bar Association, Banking Law & Fintech Report 2024: confirmation of July 2023 enactment by the Peruvian Congress.
- Harvard Kennedy School, Carr Center/Ryan commentary, “Peru’s AI Regulatory Boom: Quantity Without Depth?”: characterisation of Ley 31814 as declarative and promotional, and of Peru as the only Latin American country with two enacted AI-specific laws (31814 and 32082).
- Secondary legal analysis of D.S. 115-2025-PCM’s risk-tier structure, effective dates and supervisory-referral mechanism, cross-checked across independent summaries citing the decree’s own article numbers.







