Back to blog
ley de IAinteligencia artificialBoletín 16.821-19Ley 21.719

AI law in Chile: what the bill requires and what already binds you today

By Daniel Petrasic12 min read

Chile has no AI law yet. That does not mean anything goes

It is the most expensive confusion we see in Chilean companies today. Because no “Artificial Intelligence Act” has been published in the Diario Oficial, many executives treat the matter as a future problem and postpone it until the law is enacted. Others read the headlines about billion-peso fines and freeze projects that are perfectly legal today.

Both readings are wrong, for the same reason: they confuse the bill with what already binds you. This article separates the two, with the sources in plain sight.

The summary, if you have thirty seconds:

  • There is no AI law in force. There is a bill in its second reading in the Senate.
  • There are obligations in force that already apply to how you use AI today: personal data protection, cybersecurity and, if you sell to the State, guidelines that already show up in tender documents.
  • The fact that should change your plan: the authority that will enforce the future AI law is the same one that enforces Law 21,719 on personal data. These are not two compliance projects. They are one.

What Boletín 16,821-19 is, and where it stands

The bill is literally titled “Regulates artificial intelligence systems”. It is an Executive Message —not a parliamentary motion— filed with the Chamber of Deputies on 7 May 2024, signed by ten ministries, including the General Secretariat of the Presidency, Science, Finance, Economy, Justice and Interior. It is being processed jointly with Boletín 15,869-19.

The Chamber dispatched it on 13 October 2025 through the bill notice to the reviewing chamber. Since then it has been in its second constitutional reading in the Senate, assigned to the Committee on Future Challenges, Science, Technology and Innovation.

One detail worth checking before trusting the headlines: the most recent entry in the official tracking record is dated 4 August 2026, and corresponds to Message 233-374, which withdraws the previous urgency and files a simple urgency. Several articles in circulation still refer to the “maximum urgency” of January 2026, which has already been withdrawn. The difference is not cosmetic: urgency sets the pace at which the Executive pushes the debate.

Translated into business decisions: this will not become law next month, but it has been in process for two and a half years and has already cleared a full chamber. The text under discussion today is stable enough to plan around.


The four risk categories

The bill follows the logic of the European regulation: it does not regulate the technology, it regulates the use you make of it. It sorts uses into four levels, and everything else hangs off that classification.

  • Unacceptable risk. Uses incompatible with the respect and guarantee of fundamental rights. Absolutely prohibited.
  • High risk. Autonomous systems or safety components whose use may infringe rights. Permitted, but with strong obligations.
  • Limited risk. Uses posing non-significant risks of manipulation, deception or error. Basic obligations, mostly around transparency.
  • No evident risk. Everything else. In practice, this is where the vast majority of everyday business use lands.

Prohibited uses include systems that cause physical or psychological harm through subliminal manipulation, biometric categorisation and social scoring of individuals, and real-time remote biometric identification in publicly accessible spaces. During the first reading the list was also adjusted to cover mass scraping of facial images and emotion assessment in certain contexts.

Worth saying plainly, because it saves entire meetings: using a conversational assistant to draft, summarise documents or answer email is not a high-risk use. What moves you up the scale is deciding about people —who gets hired, who gets credit, who gets prioritised in a service— with an automated system in the loop.


Who is bound, even if the vendor sits abroad

The bill is not aimed only at those who build models. It reaches providers who place an AI system on the market or put it into service, deployersdomiciled in Chile —that is, the company that merely uses it in its operation— and importers and distributors.

And here is the point most often missed: for providers located outside Chile, the rule applies to the output generated by the system that is used in Chile. Contracting a foreign tool does not put you outside the perimeter. If its output is used here, the output is covered.

High-risk uses carry concrete obligations of continuous monitoring and incident notification within 72 hours. If that deadline sounds familiar, it is because it matches the order of magnitude already in force under personal data and cybersecurity rules: the Chilean legislator is standardising the reflex of reporting quickly.

There is also a cross-cutting transparency obligation that affects a great many marketing and service firms: any operator of AI systems generating synthetic audio, image, video or text must ensure its outputs are identifiable. An exception was added for free-licence and open-source components, unless they are commercialised.


What getting it wrong costs

Penalties under the bill range from 5,000 to 20,000 UTM depending on the severity of the infringement. With the August 2026 UTM at CLP 71,649, that is roughly CLP 358 million at the floor and CLP 1,433 million at the ceiling.

The logic is what you would expect: operating a system in the unacceptable-use category counts as the most serious infringement, while breaching the rules for high-risk uses falls into the serious tier. Proportionality criteria were added during the process to calibrate the fine.

Since the bill is still under discussion, these figures may change before enactment. What will not change is the order of magnitude: it is designed to genuinely hurt a mid-sized company.


The fact that should change your plan: the regulator already exists

If there is one thing to take from this article, it is this.

The bill does not create a new AI superintendency. It hands enforcement to the Personal Data Protection Agency: the same body created by Law 21,719, already mandated to supervise the processing of personal data in Chile. It will be the one to enforce compliance, resolve complaints from affected individuals and impose sanctions.

The practical consequences are large, and almost nobody is drawing them:

  • This is not two compliance projects, it is one. The system inventory, the processing records, the vendor clauses and the governance you build for Law 21,719 are the foundation the AI layer sits on. Doing it twice means paying twice.
  • The regulator will arrive with a learning curve behind it. It will not start from zero with you: it will come with criteria formed by enforcing data protection, which is precisely where AI touches rights.
  • Your starting point is already defined. If you do not know what personal data you process today, you will not be able to explain what your AI system does with it. That is the order, not the reverse.

What already binds you today, without waiting for the law

In April 2026 Chile’s National Congress Library published a Technical Parliamentary Advisory report on the use of AI in the Chilean State whose conclusion is worth quoting, because it dismantles the legal-vacuum narrative: Chile has opted for a gradual and sectoral approach, built on soft lawinstruments —official circulars, codes of ethics and recommendations— rather than systematic legislation.

“Soft law” sounds non-binding. In commercial practice it binds anyway, because it comes in through three other doors:

1. Law 21,719 on personal data. If you train, tune or feed a system with data about people, you are already regulated. It does not matter that you call it AI.

2. Circular No. 711, issued on 11 December 2023 and sent to 309 State bodies—ministries, undersecretariats, agencies, the Judiciary, both chambers of Congress and the Library itself—. It sets three guidelines: people-centred AI, transparency and explainability, and privacy and data use. That last one explicitly recommends not entering sensitive personal information into generative AI tools that were not contracted by the body or developed by or for it. If you sell to the State, that sentence ends up in the tender documents and in the clauses you will be asked to sign. Decree No. 12 of January 2025, which updated the National AI Policy, sits alongside it.

3. Algorithmic transparency. In August 2024 the Transparency Council approved, through Exempt Resolution No. 372, recommendations on automated and semi-automated decision systems. They reach ministries, regional governments, municipalities, the Armed Forces and public services, insofar as they use such systems. And it defines “automated decision system” deliberately broadly: no language model is required —it is enough for an algorithm to aid, assist, support or replace decision-making that later takes the form of an administrative act.

In the Judiciary, the Supreme Court adopted a Code of Ethics in 2025 whose article 17 expressly addresses responsibility in the use of AI, with a rule any company would do well to copy: the technology plays a supporting role, the decision rests on human judgement, and the tool’s role must be placed on the record.


What to do now (and what not to)

Five steps that pay off today, hold up even if the bill changes, and require waiting for no one:

1. Build the real inventory. Not the one in the IT budget: the real one. Include the tools your teams signed up for on their own and the AI features your long-standing vendors switched on without asking you. They rarely match.

2. Classify by decision, not by technology.The right question is not “does this use AI?” but “does this decide something about a person?”. If the answer is yes, that is your high risk —and probably your exposure under Law 21,719 as well.

3. Check what leaves your company. Which data goes into third-party tools, under what contract, with what no-training commitment. It is the most common gap and the cheapest to close.

4. Leave a trail. Who approved the use, what a human reviewed before the output had any effect, what was done when the system got it wrong. When an inspection comes, the difference between a fine and an observation is usually exactly that.

5. Label synthetic content. If you generate audio, image, video or text for commercial use, the requirement that it be identifiable is already written into the bill. Adopting it now costs nothing and saves you redoing campaigns later.

And three mistakes that get expensive:

  • Waiting for enactment. Data protection and public procurement obligations are already running, and they are half the work.
  • Banning AI by internal memo. It does not remove it, it makes it invisible: people keep using it from personal accounts, and there you have neither a contract nor traceability.
  • Treating it as a legal project. The lawyer drafts the policy; the person who can enforce it is the one who knows the systems. Without the technical side you are left with a document nobody can defend in an inspection.

A note on sources

This article deliberately separates what is verified from what is still under discussion. The status of the bill, the dates, the type of initiative and the urgency in force come from the official tracking record of Boletín 16,821-19 at the Chamber of Deputies. The assessment of the soft lawapproach, Circular No. 711, Decree No. 12 and Resolution No. 372 come from the National Congress Library’s Technical Parliamentary Advisory report of April 2026. The risk categories, obligations and penalty range correspond to the text under discussion and may change during the second reading: they are the best reading available today, not a law in force.

We will update this article as the bill advances. If something changes in a way that matters to your operation, better to hear it from us than from a notice.


In short

Chile does not yet have an artificial intelligence law, but it has an advanced bill, a regulator already designated —the Personal Data Protection Agency— and a set of obligations that already reach you through personal data, cybersecurity and public procurement.

The good news is that the work does not double up: whoever puts their Law 21,719 compliance in order today is building, at no extra cost, the foundation the AI law will demand tomorrow.

If you need to build the system inventory, classify your uses by risk, review the contracts with your AI vendors or leave the traceability an inspection will ask for, that is exactly what we do. Assessment, implementation and support — with technical judgement and no middlemen.

MORE

Keep reading

Got a project that fits these topics?

Contact us