Continental Postal Services of Hebland

Colombia is Preparing a Poor Copy of the EU’s AI Act


The Historic Pact party left office just weeks ago after a record that drew criticism over security, health, public finances and, above all, its failure to turn science, technology and innovation into a genuine state priority. Before leaving office, however, its congressional caucus moved to address an issue it had not pursued with sufficient urgency during four years in government by introducing a bill to regulate artificial intelligence in Colombia.

Bill 025 of 2026, currently before the Colombian House of Representatives, seeks to regulate AI and ensure its ethical and responsible development. The bill applies to developers, providers and deployers of AI systems and establishes specific duties for systems that may significantly affect fundamental rights or other protected interests. These include risk and impact assessments, transparency, human oversight and monitoring, alongside public oversight responsibilities and sanctions for non-compliance.

There is only one problem. The country does not need another ambitious law that looks good on paper but ignores the technological, institutional and economic conditions in which it would have to operate.

The bill’s purpose is legitimate. Colombia needs rules for a technology that is already transforming work, education, public administration, security and the exercise of fundamental rights. At first sight, the bill follows a familiar international approach. It adopts risk-based regulation, establishes obligations for certain AI systems and proposes mechanisms for impact assessment, oversight and governance.

Much of this resembles the architecture of the European Union’s Artificial Intelligence Act. But there is a fundamental difference between learning from the European model and attempting to reproduce it.

The problem is not looking to Europe

The EU AI Act did not emerge in a vacuum. It operates within an integrated market of hundreds of millions of people, supported by national authorities, substantial administrative capacity, technical expertise and significant financial resources. It is also part of a broader legal and institutional system capable of distributing responsibilities among developers, providers, deployers and regulators. Colombia can adopt European principles. What it cannot simply import are the institutional capacities that make those principles enforceable.

This is a classic problem of regulatory transplantation. A framework designed for one institutional and economic environment can lose effectiveness when transferred to another without sufficient adaptation. In Colombia, the risk is particularly serious. A sophisticated regulatory framework could create obligations that local companies and public institutions are unable to meet while doing little to constrain the foreign companies that actually develop the most powerful systems. That would not be effective regulation. It would be regulatory mimicry.

Regulation also requires capacity

Among its key proposals, the bill would require impact assessments, establish oversight mechanisms and create institutional structures for AI governance. These measures may be reasonable in principle. What is far less clear is who would implement them, how responsibilities would be distributed and with what resources. This is not simply a question of public finances. It is a question of state capacity.

The comparison with the EU AI Act is particularly relevant in the allocation of responsibilities. Under the European framework, providers of high-risk systems are responsible for documentation, risk management and demonstrating compliance, while deployers are primarily responsible for how those systems are used, including human oversight and monitoring. This distinction matters in Colombia, where a local company may deploy a high-risk system developed abroad without access to its underlying model, training data or internal documentation. Reproducing these obligations without considering who actually controls the technology could place the greatest burden on those least able to meet it.

Regional human rights law has long recognized a difference between formally recognizing a right and creating the conditions necessary to guarantee it. See, for instance, Velásquez Rodríguez v. Honduras and Suárez Peralta v. Ecuador before the Inter-American Court of Human Rights. A legal obligation that cannot be monitored, investigated or enforced risks becoming little more than a declaration. The same applies to AI regulation. It is not enough to require impact assessments or algorithmic audits if the authorities responsible for supervising them lack the necessary technical expertise, infrastructure, information and budget.

Regulating technology requires much more than passing legislation. It requires officials who understand technological systems, inspection mechanisms, sanctions and cooperation with foreign regulators. Otherwise, Colombia risks creating a law that exists mainly on paper.

Who decides what is high risk?

There is another problem that deserves greater constitutional attention. Classifying an AI system as high risk is not merely a technical decision. That classification can determine which legal obligations apply, what uses are restricted and, in some cases, whether a system can be deployed at all. That makes it important to ask who defines the criteria and under what safeguards.

From the perspective of algorithmic due process, decisions that may affect fundamental rights should be transparent, open to challenge and subject to effective review. Article 5 establishes the categories and general criteria for risk classification, but also allows the national AI authority to establish and update the list of high-risk uses through a reasoned administrative act and after public consultation. Article 7 designates the Ministry of Science, Technology and Innovation as that authority and gives it power to issue binding technical recommendations on the risk level of AI systems.

Although the bill reserves final intervention measures to the authorities with relevant legal powers, this raises questions about how much discretion an executive authority should have in determining which systems trigger enhanced legal obligations. Technical expertise is indispensable, but decisions with significant consequences for fundamental rights should remain subject to clear legislative criteria and effective review.

The Colombian paradox

There is a deeper problem. Colombia may require a company to explain, audit or assess an AI system that it uses. But what happens when that company does not actually control the technology?

A small Colombian company may rely on a model developed by a foreign company. It may have no access to the model’s training data, architecture, evaluation procedures or internal safeguards. It can deploy the technology, but it cannot meaningfully govern it. This reveals one of the great asymmetries of today’s technological order. Countries in the Global South increasingly consume technological infrastructures developed by companies concentrated in a handful of countries. They may regulate how those systems are used without having meaningful control over the systems themselves.

Colombia could therefore end up imposing the heaviest regulatory obligations on those who are closest to the consequences of AI, rather than on those who possess the greatest capacity to shape the technology. This is where the debate over technological dependency and the coloniality of data becomes relevant. The issue is not simply who owns the data. It is also who controls the infrastructure, the models, the computing power and the knowledge required to transform data into technological and economic power. A genuinely sovereign AI policy should confront that distribution of power rather than simply reproduce regulatory categories developed elsewhere.

Regulate better, not more

None of this means that Colombia should refrain from regulating AI. It means that regulation should be proportional to the risks and compatible with the country’s actual institutional capacity. The strongest safeguards should initially focus on areas where AI can cause particularly serious harm to human rights, including health, justice, security, surveillance and public services. Obligations should also vary according to the level of risk and, crucially, according to the degree of control each actor actually exercises over the technology.

It makes little sense to require a small Colombian company to guarantee the explainability of a closed model whose operation it cannot inspect. The bill places obligations on actors involved in the development and implementation of AI, but does not establish the same clear extraterritorial reach as the EU AI Act over foreign providers. This could leave local deployers carrying obligations over technologies whose underlying models, data and documentation remain outside their control. The objective of AI regulation should not be to look European. It should be to work in Colombia.

The Historic Pact’s proposal starts from a legitimate concern, but it appears to confuse regulatory sophistication with regulatory capacity. Colombia does not need to copy the EU AI Act. It should adopt its risk-based approach and clearer allocation of responsibilities between providers and deployers, while adapting compliance requirements to Colombia’s institutional capacity and technological ecosystem. The more fundamental question is where the technological power that this law seeks to regulate actually resides.

The future of AI governance will not be determined only by what machines are allowed to do. It will also depend on who has the power to build them, who controls the infrastructure on which they operate and who has the real capacity to impose limits on them. That is the regulatory question Colombia should be asking before it copies Europe’s answers.



Source link

Leave A Reply

Your email address will not be published.