The Regulation applies the principles of Law No. 31814 to AI development, implementation and use across public entities, the private sector and the wider national AI ecosystem. It distinguishes undue or prohibited use, high-risk use and acceptable use. Prohibited uses include manipulative or deceptive techniques, lethal autonomous weapons without human oversight, unlawful or disproportionate mass surveillance, sensitive-trait inference from biometric data, restricted real-time biometric identification in public spaces, and crime prediction based solely on profiling or personal characteristics. High-risk uses include critical national assets, specified educational and employment decisions, access to social programmes, credit assessment, consequential health uses and emotion inference in workplaces or educational institutions, subject to the stated exceptions. The Regulation requires additional safeguards for these systems, including algorithmic transparency, human oversight, security auditing and personal-data protection by design. PCM, through SGTD, leads governance, issues standards and guidance and supervises compliance; implementation is progressive according to the capacities and resources of the actors in the National Digital Transformation System.
Regulation
Verified record
- Risk classification summary
- Three operational categories: undue/prohibited use; high-risk use allowed only with additional controls; and acceptable use, which remains subject to the governing principles. High-risk areas include critical assets, education, employment, social programmes, credit, consequential healthcare and specified emotion inference.
- Requirements summary
- Apply risk-proportionate safeguards; do not deploy prohibited uses; provide algorithmic transparency and meaningful human oversight for high-risk systems; conduct the required security auditing; protect personal data by design; and follow the Regulation’s progressive implementation timetable. Duties are actor- and use-specific, so do not state that every listed control applies identically to every private organisation.
- Affected entities
- Public-administration entities, private-sector organisations and other actors that develop, implement or use AI in Peru; public institutions and operators of high-risk systems bear the most specific operational safeguards. Academia, civil society and citizens also participate in the governance and innovation framework but should not be described as universally regulated operators.
- Enforcement summary
- PCM, through SGTD, is the national technical and regulatory authority: it directs, evaluates and supervises AI use and promotes standards, guidelines and good practices. The cited Regulation does not create a private right of action or a self-contained AI enforcement tribunal.