Peru’s AI Law Now Has an Operating Regulation
Peru approved Supreme Decree 115-2025-PCM on 9 September 2025, giving Law 31814 an operating regulation. The framework classifies AI uses by risk and connects innovation to transparency, human oversight, privacy, security and accountability.
The original law promoted artificial intelligence for economic and social development. The regulation makes that objective more concrete across 36 articles and assigns the Presidency of the Council of Ministers, through the Secretariat of Government and Digital Transformation, the national technical and regulatory role.
This is not a rule only for model developers. Public and private organisations that implement or use AI systems need to understand the level of risk created by a particular use and build governance around it.
Risk classification determines the safeguards
The regulation distinguishes prohibited uses and high-risk applications. Prohibited practices include specified uses that violate fundamental rights, such as manipulative or discriminatory applications and mass surveillance without a legal basis. High-risk uses can include systems affecting health, education, justice, finance or access to essential programmes and services.
Classification should focus on purpose and impact, not merely the technical model. The same underlying technology may be low risk when suggesting document formatting and high risk when influencing eligibility, diagnosis or employment.
High-risk AI needs a documented control system
Entities using high-risk systems need to identify and evaluate risks, implement suitable risk-management measures and conduct an impact assessment. Data used for training, validation and testing should be assessed for quality, relevance, representativeness and inappropriate bias.
Records should support traceability, and human supervision must be able to correct, modify or stop a system. These requirements make production monitoring as important as approval. A model that was acceptable during testing can become unreliable as data, users or operating conditions change.
Transparency depends on the effect on people
Users of high-risk systems should receive clear, prior information about the purpose, operation and decisions the system can make. When AI affects rights, people should receive an understandable explanation of the criteria and factors influencing the result.
The regulation also uses visible labelling as a transparency measure for publicly disseminated AI-generated content. A generic statement hidden in terms of service is unlikely to provide the same practical notice at the point of interaction.
Personal data remains governed by privacy law
AI systems must comply with Peru’s Personal Data Protection Law and its regulation. Measures include a legitimate basis for processing, data minimisation, security by design and particular care with sensitive data.
An AI approval process should therefore connect to existing privacy records and rights workflows. If a person corrects or deletes data in the source system, the organisation needs to understand what that means for retrieval, outputs, logs and future model use.
What organisations should do
- Inventory AI systems, pilots and embedded vendor functions.
- Classify each use by purpose, affected people and potential impact.
- Run impact assessments and define risk controls for high-risk systems.
- Design clear notices, explanations and meaningful human intervention.
- Monitor data quality, bias, security and performance after deployment.
The regulation turns principles into lifecycle duties
Peru’s framework is designed to support innovation, but it does so by linking higher-risk uses to stronger evidence and safeguards. The practical challenge is not writing an AI policy. It is ensuring every material system has an owner, a risk classification and controls that continue to work after launch.
Official sources
- Presidency of the Council of Ministers: Supreme Decree 115-2025-PCM
- Official text of the AI regulation
- Government guidance on the AI regulation
This article provides general information and is not legal advice.
Continue the series: LATAM Cyber & Digital Law Series index


