Skip to content

Europe

Independent · Brussels & Berlin

Technology · AI regulation

Colombia's AI bill mimics EU rules but lacks enforcement capacity

Bill 025 of 2026 copies the European risk-based framework while ignoring the institutional infrastructure that makes it workable in Brussels.

By , Technology Editor

Published

7 min read

Colombia's Congress is debating an artificial intelligence bill that reads as though it were drafted in Brussels but will have to function in Bogotá. Bill 025 of 2026, introduced by the congressional caucus of the outgoing Historic Pact party weeks before it left office, adopts the risk-based architecture of the European Union's AI Act almost wholesale. It defines risk categories, mandates impact assessments, requires transparency and human oversight, and creates a national AI authority with powers to update the list of high-risk systems. What it does not do is explain how a country with a fraction of the EU's administrative capacity, technical expertise and financial resources will enforce any of it.

A European blueprint without European infrastructure

The EU AI Act did not emerge in isolation. It sits atop an integrated market of 450 million people, supported by national regulators in each member state, a network of notified bodies, and a legal order that can distribute obligations across developers, providers, deployers and supervisory authorities. Colombia has none of that infrastructure. Its data protection authority, created only in 2021, is still building basic operational capacity. The Ministry of Science, Technology and Innovation, designated as the AI regulator under the bill, has a budget that reflects the country's broader fiscal constraints. Passing a law that assumes the existence of a European-grade enforcement machine does not create that machine.

This is a textbook case of regulatory transplantation failure. When a framework designed for one institutional environment is moved to another without adaptation, the result is often a set of obligations that local actors cannot meet and foreign actors can ignore. In Colombia's case, the asymmetry is acute. The most powerful AI systems are developed by companies concentrated in the United States and China. Colombian firms and public agencies are overwhelmingly deployers, not providers. They integrate models they did not build, trained on data they did not collect, running on infrastructure they do not control.

The deployer-provider trap

The EU AI Act distinguishes carefully between providers, who build and place high-risk systems on the market, and deployers, who use them under their own authority. Providers bear the heavy obligations: technical documentation, risk management systems, conformity assessment, post-market monitoring. Deployers face lighter but still significant duties: human oversight, input data quality, incident reporting. This division works in Europe because many providers are European or have EU establishments, and the regulation has extraterritorial reach. Colombia's bill replicates the deployer obligations but does not establish equivalent extraterritorial authority over foreign providers. A small Colombian startup using a closed model from a US company could be legally required to guarantee explainability and conduct algorithmic audits of a system whose architecture, training data and evaluation procedures it cannot inspect.

The problem is not theoretical. In health, justice, surveillance and public administration, Colombian entities are already procuring AI-driven tools from abroad. The bill would impose compliance costs on the Colombian side of the transaction while leaving the upstream decisions about model design, data governance and risk mitigation entirely outside Colombian jurisdiction. That is not effective regulation. It is a transfer of regulatory burden to the party least able to influence the technology.

Executive discretion and constitutional questions

Article 5 of the bill sets out general criteria for risk classification but allows the national AI authority, the Ministry of Science, Technology and Innovation, to establish and update the list of high-risk uses through a reasoned administrative act after public consultation. Article 7 gives the ministry power to issue binding technical recommendations on the risk level of specific systems. In effect, an executive body would decide which AI applications trigger the most onerous legal obligations, with final intervention measures reserved to other authorities. From the perspective of algorithmic due process, this raises serious questions. Decisions that determine whether a system can be deployed at all, and under what constraints, affect fundamental rights. The Inter-American Court of Human Rights has long held that formally recognising a right is not enough; the state must create the conditions to guarantee it. A classification power this broad, vested in a ministry without clear legislative criteria or effective judicial review, risks becoming a regulatory blank cheque.

Technological dependency and the coloniality of data

Beneath the technical debate lies a structural one. Countries in the Global South increasingly consume technological infrastructures developed by companies headquartered in a handful of nations. They may regulate how those systems are used, but they have little meaningful control over the models, the computing power, or the knowledge required to transform data into economic and technological power. The bill does not confront this asymmetry. It regulates the Colombian end of the value chain while leaving the upstream concentration of power untouched. A genuinely sovereign AI policy would ask who controls the infrastructure, who builds the models, and who has the real capacity to impose limits on them. Instead, the bill reproduces regulatory categories developed for a European context where the power distribution is different.

What proportional regulation could look like

None of this argues against AI regulation in Colombia. The technology is already transforming work, education, security and public services, and the absence of rules creates its own risks. But regulation must be proportional to the risks that actually materialise in Colombia and compatible with the institutions that must enforce it. The strongest safeguards should focus first on domains where AI can cause severe harm to fundamental rights: health diagnostics, judicial decision support, police surveillance, social security allocation. Obligations should scale not only with risk level but with the degree of control each actor exercises over the technology. A deployer that cannot access a model's internals should not be held to the same explainability standard as its provider. The bill's risk-based approach is sound in principle; its failure is in assuming that Colombian state capacity can match European ambition.

There is also a sequencing question. Before creating new administrative structures, Colombia could strengthen existing sectoral regulators, the health superintendency, the financial superintendency, the data protection authority, giving them the technical teams and legal mandates to oversee AI in their domains. This builds enforcement capacity where it already exists rather than assuming a new central authority can do everything at once. The EU itself took years to build the governance architecture that now supports the AI Act. Colombia cannot import the result without the process.

Sources

  1. Tech Policy Press

    techpolicy.press · 2026-08-25

People mentioned

  • Daniel Arias Rivera

    Author of the source analysis, Independent commentator

Organisations

Historic Pact party · Colombian House of Representatives · Ministry of Science, Technology and Innovation · European Union · Inter-American Court of Human Rights

Related analysis

Selected because they share topics with this article

The newsletter

One important European story. Explained properly.

Delivered to your inbox on the days we publish. No daily digest, no push notifications, no advertising.

We store your address only to send the briefing. Unsubscribe in one click.