Chile's AI bill: risk classification and obligations for companies

Chile's Artificial Intelligence bill is going through the Senate. Although it is not law yet, it already defines the framework to come: risk…
· AI and data compliance
Chile's Artificial Intelligence bill is going through the Senate. Although it is not law yet, it already defines the framework to come: risk classification, concrete prohibitions, principles companies will have to comply with. If you use AI in your organisation —and today almost every organisation uses something— it pays to understand where the regulation is heading before it arrives.
Where this bill comes from
In October 2025 Chile's Chamber of Deputies approved the bill regulating artificial intelligence systems, and it is currently going through the Senate, where it is being studied by the Committee on Future Challenges. You can follow the progress of the process on the Chamber's site. Its design follows the approach of the European AI Act, which Chile takes as a reference.
The central principle: regulate according to risk
The bill does not prohibit AI. What it does is establish that the greater the risk of affecting fundamental rights, the greater the operator's obligations. That principle of proportionality produces four categories:
- Unacceptable risk — prohibited: uses directly incompatible with fundamental rights. The clearest example is mass social scoring systems (such as those used by some authoritarian governments to assess the population's behaviour) or indiscriminate biometric surveillance in public spaces.
- High risk — strict obligations: systems affecting sensitive decisions: credit, employment, health, education, criminal justice, critical infrastructure. They require technical documentation, bias assessments, mandatory human oversight and traceability.
- Limited risk — basic transparency: systems with potential for manipulation or minor error. For example, a chatbot answering as if it were human must identify itself as an automated system.
- No obvious risk: low-impact uses with minimal restrictions (spam filters, basic productivity tools).
The principles every AI must meet
The bill sets out cross-cutting principles applying to every system, whatever its risk category:
- Human oversight: it must always be possible for a human to intervene in, correct or stop an AI system.
- Technical safety: systems must be robust and resistant to failures and attacks.
- Data protection: AI processing personal data must comply with Ley 21.719 (fully in force from December 2026).
- Fairness: systems cannot discriminate by gender, race, origin or other protected characteristics.
- Transparency: the affected user must be able to know they are interacting with an AI system and, in significant decisions, obtain an explanation of the outcome.
What the bill creates: the Technical Advisory Council on AI
The bill creates a Technical Advisory Council on AI under the Ministry of Science, Technology, Knowledge and Innovation. Its functions include proposing which systems classify as high or limited risk, assessing the law's implementation every three years, and encouraging responsible innovation. It is not a sanctioning body; that function rests with the sector ministries and, for anything involving personal data, with the Personal Data Protection Agency.
A concrete example: a credit scoring system
A bank or fintech using an AI model to approve or reject credit falls into the high risk category under the bill: the decision affects significant economic rights. Under the future law, that bank would have to document the model, carry out periodic bias audits, guarantee that a human analyst can review the outcome if the client asks, and demonstrate that the model was trained without using protected categories such as gender or ethnicity as discriminatory variables.
Sanctions: up to 20.000 UTM
The bill provides for fines of up to 20.000 UTM for anyone breaching the rules. The exact amount depends on the seriousness of the breach, the risk category of the system involved and whether it is a repeat offence. It is not a small figure: it represents tens of millions of pesos at the current UTM value.
What to do while the bill goes through
- Inventory which AI systems you use and assess which risk category they would fall into under the bill.
- Review your data policy: AI processing personal data is already subject to Ley 21.719 once it comes into force in December 2026.
- Implement human oversight in automated decisions significantly affecting people. Doing it now reduces legal and reputational risk already, before it becomes compulsory.
- Follow the process in the Senate to keep track of amendments introduced to the text approved by the Chamber.
In summary
Chile is building risk-based AI regulation, similar to the European model. If your organisation uses automated systems affecting decisions about people, the direction is clear: document, oversee, audit and be transparent. The bill does not seek to hold back innovation but to give it a framework that protects rights. Adapting before it becomes compulsory is always easier than doing it under pressure.
Sources: AI Bill — Chamber of Deputies; MinCiencia Chile. Informational content: it does not replace professional advice.
— Mindset & Code · Legal-Tech Chile · law and technology, explained simply.
You may also like
- Ley 21.663: what the Cybersecurity Framework Act requires of companies in Chile
- Privacy and the right to be forgotten: your rights over your data
- Algorithmic law: who is liable when a machine decides