

In May 2024, the Presidency of the Republic introduced the Artificial Intelligence Bill in Chile. The bill is currently before the Senate in its second constitutional review. Its main objective is to strike a balance between promoting technological innovation and economic development while ensuring the protection of fundamental rights.
This bill is the culmination of a broader public policy strategy that includes the 2023 update of Chile's National AI Policy and the implementation of UNESCO's Readiness Assessment Methodology (RAM).
In this article, we take a closer look at the bill to examine how Chile intends to regulate artificial intelligence, at a time when only a few months remain before the country's new Personal Data Protection Law (Law No. 21,719) comes into force.
The bill regulates systems based on the risk they pose to citizens and therefore makes a distinction between:
| Risk category | Cases | Legal Status |
| Unacceptable | Subliminal Manipulation: Imperceptible techniques that induce actions harmful to physical or mental health. (Exception: Therapeutic purposes with express consent). Exploitation of Vulnerabilities: Uses that take advantage of age, disability, or socioeconomic situation to alter behavior in a harmful manner. Sensitive Biometric Categorization: Classification based on sensitive data or inferences from these attributes. (Exception: Authorized therapeutic purposes). Generic Social Scoring: Evaluation of social behavior that results in discriminatory treatment. Real-Time Remote Biometric Identification: Prohibited in public spaces. (Exception: Strict use by authorities for public security and criminal prosecution). Facial Scraping: Non-selective extraction of facial images from the internet or CCTV to create databases. Emotional State Assessment: Systems that infer emotions in employment, educational, border management, or criminal law enforcement contexts. | Forbidden |
| High Risk | Systems with the potential to significantly affect health, safety, environment, or fundamental rights. | Regulated: Risk Management: Iterative and continuous process throughout the entire lifecycle. Data Governance: Training of models with high-quality and integrity data. Technical Documentation: Intelligible manuals that demonstrate regulatory compliance. Event Logging: Traceability of security and operability. Transparency for Users: Design that enables interpretation of output information. Human Oversight: Monitoring by trained natural persons to prevent risks. Cybersecurity: Resilience and accuracy by design and by default. |
| Limited Risk | Systems with non-significant risks of manipulation, deception, or error in interaction. | Transparency (Duty to inform) |
| No Obvious Risk | All other systems that do not qualify in the previous categories. | No specific obligations |
Article 13 establishes a mechanism for reporting serious incidents to the Personal Data Protection Agency, with a maximum deadline of 72 hours from when the operator becomes aware of the causal link between the system and the incident.
These serious incidents are defined as those that cause death, serious harm to health, disruption of critical infrastructure, violation of fundamental rights, or environmental damage.
For governance and regulatory compliance, the bill is based on two oversight bodies:
The bill is not limited to restricting but rather dedicates an entire section to support measures, among which the following stand out:
The enforcement framework provides for three levels of infractions:
| Penalty | Conduct | Maximum fine |
| Very serious | Use of unacceptable risk systems | 20.000 UTM |
| Serious | Non-compliance with rules for high-risk systems | 10.000 UTM |
| Mild | Failure to comply with transparency obligations (limited risk) | 5.000 UTM |
The enforcement procedure will be carried out by the Agency, but independently of the administrative route, Article 28 recognizes a civil liability action in favor of anyone who suffers damage from the use of an AI system.
The Chilean AI bill seeks to balance the protection of people's fundamental rights against the risks of AI without hindering innovation in a sector that Chile has sought to position as strategic in the region. The adoption of a risk-based approach, the creation of specialized institutional frameworks, and the inclusion of support mechanisms such as regulatory sandboxes are signs that the legislator is seeking proportional regulation, rather than a blanket prohibition.
That said, the bill is still in the legislative process, so its final content could undergo relevant changes in Congress. So if you don't want to miss anything, keep visiting our blog.
This bill could directly impact your compliance obligations for your ecommerce website. At Lawwwing we help you anticipate these regulatory changes and draft your AI Policy tailored to your business. That's why we offer you solutions like Vericta for verifying content generated or modified through AI.