Regulatory Radar
AI and data protection regulation updates, region by region — EU, US, and Latin America. No noise: only what actually changes.
Regulation of Law 31814 — the first fully enacted AI law in Latin America
Peru published the implementing regulation for its AI law, making it the first country in the region with a fully enacted AI law (not just a bill). Risk-tiered framework, prohibited practices, and mandatory human oversight for high-risk uses — structurally close to the EU AI Act.
Bill 2338 passes the Senate
The most advanced framework in the region after Peru's. Closely modeled on the AI Act, it prohibits social scoring and mass surveillance, and imposes strict oversight on high-risk applications (hiring, clinical diagnostics, credit scoring). Still pending approval by the Chamber of Deputies.
Federal AI Law under Senate discussion
Mexico's proposed federal AI law is under Senate discussion, with passage expected during 2026. It isn't law yet — specific obligations may still change before final approval.
Risk-tiered bill, plus an updated National AI Policy
Chile combines an already-updated National AI Policy with a risk-based bill focused on transparency, fairness, and human oversight, still moving through Congress.
First country in the region to sign the Council of Europe's AI Framework Convention
Uruguay became the first Latin American country to sign the Council of Europe's binding treaty on AI, human rights, democracy, and the rule of law — a signal it wants to lead the region's regulatory approach.
No AI-specific law yet — operating through general data protection
These countries don't yet have an AI-specific law; AI uses that process personal data are already covered by their general data protection laws (Law 25.326 in Argentina, Law 1581 in Colombia). Argentina shows recent Congressional movement on AI-related election manipulation and privacy.
AI Act's decisive milestone: most obligations become enforceable
From this date, high-risk system obligations stop being "preparation" and become genuinely enforceable. If your company operates AI in the EU and hasn't completed its system inventory, this is the quarter to close that gap.
NIS2 transposition remains uneven across member states
Not all EU countries have completed national transposition of the NIS2 Directive at the same pace — if you operate across several European countries, check the specific status in each jurisdiction rather than assuming one EU-wide date.
No federal AI law — NIST AI RMF as the de facto standard
The US still has no federal AI law. Regulatory activity sits with agencies, executive orders, and, increasingly, a growing number of state laws. The NIST AI RMF has become the reference vocabulary corporate buyers and insurers use to evaluate vendors.